<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mohamed+Alfateh</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Mohamed+Alfateh"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Mohamed_Alfateh"/>
		<updated>2026-06-01T15:26:41Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256388</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256388"/>
				<updated>2019-12-16T13:10:34Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Chapter Meeting  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Y2019 Challenges and the Planning for Y2020 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
In this meeting we will discuss Y2019 Progress &amp;amp; achievements and the planning for Y2020. &amp;lt;br /&amp;gt; &lt;br /&gt;
The attendance is open, please join the chapter mailing list or send us an email to confirm your attendance. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
To join remotely, please refer to the meeting invitation below &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
26 December 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- OWASP Cairo Chapter Activities in 2019 [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt; 17:00 to 17:30&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Open Discussion for the Y2020 Planning &amp;lt;br /&amp;gt; 17:30 to 18:30&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''To join remotely'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Topic: OWASP Cairo Chapter Meeting&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: Dec 26, 2019 04:00 PM Cairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Join Zoom Meeting &amp;lt;br /&amp;gt;&lt;br /&gt;
https://zoom.us/j/317320557 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Meeting ID: 317 320 557 &amp;lt;br /&amp;gt;&lt;br /&gt;
Password: Please refer to the mailing list or just drop us an email &amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
One tap mobile &amp;lt;br /&amp;gt;&lt;br /&gt;
+19294362866,,317320557# US (New York) &amp;lt;br /&amp;gt;&lt;br /&gt;
+16699006833,,317320557# US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Find your local number: https://zoom.us/u/acqCytjmkN &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256299</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256299"/>
				<updated>2019-12-11T13:17:11Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Chapter Meeting  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Y2019 Challenges and the Planning for Y2020 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
In this meeting we will discuss Y2019 Progress &amp;amp; achievements and the planning for Y2020. &amp;lt;br /&amp;gt; &lt;br /&gt;
The attendance is open, please join the chapter mailing list or send us an email to confirm your attendance. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
To join remotely, please refer to the meeting invitation below &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
VIP Room (tentatively) - ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
26 December 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- OWASP Cairo Chapter Activities in 2019 [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt; 17:00 to 17:30&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Open Discussion for the Y2020 Planning &amp;lt;br /&amp;gt; 17:30 to 18:30&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''To join remotely'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Topic: OWASP Cairo Chapter Meeting&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: Dec 26, 2019 04:00 PM Cairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Join Zoom Meeting &amp;lt;br /&amp;gt;&lt;br /&gt;
https://zoom.us/j/317320557 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Meeting ID: 317 320 557 &amp;lt;br /&amp;gt;&lt;br /&gt;
Password: Please refer to the mailing list or just drop us an email &amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
One tap mobile &amp;lt;br /&amp;gt;&lt;br /&gt;
+19294362866,,317320557# US (New York) &amp;lt;br /&amp;gt;&lt;br /&gt;
+16699006833,,317320557# US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Find your local number: https://zoom.us/u/acqCytjmkN &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256298</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256298"/>
				<updated>2019-12-11T13:12:48Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Chapter Meeting  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Y2019 Challenges and the Planning for Y2020 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
In this meeting we will discuss Y2019 Progress &amp;amp; achievements and the planning for Y2020. &amp;lt;br /&amp;gt; &lt;br /&gt;
The attendance is open, please join the chapter mailing list or send us an email to confirm your attendance. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
TO join remotely, please refer to the meeting invitation below &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
26 December 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- OWASP Cairo Chapter Activities in 2019 [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt; 17:00 to 17:30&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Open Discussion for the Y2020 Planning &amp;lt;br /&amp;gt; 17:30 to 18:30&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''To join remotely'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Topic: OWASP Cairo Chapter Meeting&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: Dec 26, 2019 04:00 PM Cairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Join Zoom Meeting &amp;lt;br /&amp;gt;&lt;br /&gt;
https://zoom.us/j/317320557 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Meeting ID: 317 320 557 &amp;lt;br /&amp;gt;&lt;br /&gt;
Password: Please refer to the mailing list or just drop us an email &amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
One tap mobile &amp;lt;br /&amp;gt;&lt;br /&gt;
+19294362866,,317320557# US (New York) &amp;lt;br /&amp;gt;&lt;br /&gt;
+16699006833,,317320557# US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Find your local number: https://zoom.us/u/acqCytjmkN &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256297</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256297"/>
				<updated>2019-12-11T13:10:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Chapter Meeting  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Y2019 Challenges and the Planning for Y2020 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
This meeting is to evaluate Y2019 Progress &amp;amp; achievements and the planning for Y2020. &amp;lt;br /&amp;gt; &lt;br /&gt;
The attendance is open, please join the chapter mailing list or send us an email to confirm your attendance. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
TO join remotely, please refer to the meeting invitation below &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
26 December 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- OWASP Cairo Chapter Activities in 2019 [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt; 17:00 to 17:30&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Open Discussion for the Y2020 Planning &amp;lt;br /&amp;gt; 17:30 to 18:30&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To join remotely:&amp;lt;br /&amp;gt;&lt;br /&gt;
Topic: OWASP Cairo Chapter Meeting&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: Dec 26, 2019 04:00 PM Cairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Join Zoom Meeting &amp;lt;br /&amp;gt;&lt;br /&gt;
https://zoom.us/j/317320557 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Meeting ID: 317 320 557 &amp;lt;br /&amp;gt;&lt;br /&gt;
Password: Please refer to the mailing list or just drop us an email &amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
One tap mobile &amp;lt;br /&amp;gt;&lt;br /&gt;
+19294362866,,317320557# US (New York) &amp;lt;br /&amp;gt;&lt;br /&gt;
+16699006833,,317320557# US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Dial by your location &amp;lt;br /&amp;gt;&lt;br /&gt;
        +1 929 436 2866 US (New York)&amp;lt;br /&amp;gt;&lt;br /&gt;
        +1 669 900 6833 US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Find your local number: https://zoom.us/u/acqCytjmkN &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256296</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256296"/>
				<updated>2019-12-11T13:09:02Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: Adding the Chapter meeting details&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Chapter Meeting  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Y2019 Challenges and the Planning for Y2020 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The meeting to evaluate Y2019 Progress &amp;amp; achievements and the planning for Y2020. You can join remotely &amp;lt;br /&amp;gt; &lt;br /&gt;
The attendance is open, please join the chapter mailing list or send us an email to confirm your attendance &amp;lt;br /&amp;gt;&lt;br /&gt;
Please refer to the meeting invitation below &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
26 December 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- OWASP Cairo Chapter Activities in 2019 [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt; 17:00 to 17:30&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Open Discussion for the Y2020 Planning &amp;lt;br /&amp;gt; 17:30 to 18:30&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To join remotely:&amp;lt;br /&amp;gt;&lt;br /&gt;
Topic: OWASP Cairo Chapter Meeting&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: Dec 26, 2019 04:00 PM Cairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Join Zoom Meeting &amp;lt;br /&amp;gt;&lt;br /&gt;
https://zoom.us/j/317320557 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Meeting ID: 317 320 557 &amp;lt;br /&amp;gt;&lt;br /&gt;
Password: Please refer to the mailing list or just drop us an email &amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
One tap mobile &amp;lt;br /&amp;gt;&lt;br /&gt;
+19294362866,,317320557# US (New York) &amp;lt;br /&amp;gt;&lt;br /&gt;
+16699006833,,317320557# US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Dial by your location &amp;lt;br /&amp;gt;&lt;br /&gt;
        +1 929 436 2866 US (New York)&amp;lt;br /&amp;gt;&lt;br /&gt;
        +1 669 900 6833 US (San Jose) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Find your local number: https://zoom.us/u/acqCytjmkN &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256295</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=256295"/>
				<updated>2019-12-11T12:56:54Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Chapter Meeting  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The meeting to evaluate the Y2019 Progress and the planning for Y2020.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You can join remotely, we will share the meeting Link soon &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
26 December 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- OWASP Cairo Chapter Activities in 2019 [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt; 17:00 to 17:30&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Open Discussion for the Y2020 Planning &amp;lt;br /&amp;gt; 17:30 to 18:30&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=254212</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=254212"/>
				<updated>2019-08-26T19:25:10Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
InterContinental City Stars Cairo - Hambra Ballroom (-2), Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=254207</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=254207"/>
				<updated>2019-08-26T18:30:13Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=254205</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=254205"/>
				<updated>2019-08-26T18:29:34Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Registration link: https://forms.gle/o8PrYk6GCLbG2uAm8&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253723</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253723"/>
				<updated>2019-08-14T13:11:10Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253722</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253722"/>
				<updated>2019-08-14T13:10:28Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;(By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253721</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253721"/>
				<updated>2019-08-14T13:09:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253720</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253720"/>
				<updated>2019-08-14T13:09:07Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Egypt Cyber and Privacy Security Requirements for Software Developers. &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, we will discuss number of Cyber law clauses that should be considered in developing software applications, we will go through the final draft of the executive regulation to highlight the additional controls that should be implemented in the applications, that will add extra layer of security and ensure the compliance with the Cyber law requirements. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253514</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253514"/>
				<updated>2019-08-03T21:13:12Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; Event starts by 5 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Compliance requirements for Egyptian Cyber ​​Law and Privacy Law: Application Development perspective &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253513</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253513"/>
				<updated>2019-08-03T21:11:32Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Compliance requirements for Egyptian Cyber ​​Law and Privacy Law: Application Development perspective &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Mohamed Alfateh'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Alfateh is the OWASP Cairo chapter leader, he has deep experience in secure SDLC, code review &amp;amp; application threat modeling, DevSecOps and security compliance. Mohamed has many contributions for OWASP, he is the author for the “OWASP application threat modeling cheat sheet” and a board member of OWASP Middle-East. He is currently Sr. Consultant at ZINAD IT, holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA/LI &amp;amp; Lead SCADA Security Professional certificates.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day Two'''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Call For Paper'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/forms/d/e/1FAIpQLSd01JoNAUKNXGvWe7M17T2LTP3a9E3HGVa7xT4E9uetS6rQxg/viewform?vc=0&amp;amp;c=0&amp;amp;w=1&lt;br /&gt;
 Call For Paper]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253485</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253485"/>
				<updated>2019-08-02T16:22:13Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
Day Two Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Day One is open and free.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Event Speakers '''&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Jim Manico'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Georgia Weidman'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event announcing pended on foundation review/approval &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253484</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253484"/>
				<updated>2019-08-02T16:16:48Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== AppSec Africa  ===== &lt;br /&gt;
OWASP Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''AppSec Africa Day One'''&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The event hall has a limited number of seats. If you are interested to attend please try to be there before the session start by a good amount of time and be sure to register for the event.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
1st September 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top Ten Proactive Controls 2018&amp;lt;br /&amp;gt; (By: '''Jim Manico''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Software developers are the foundation of any application. In order to achieve secure software, developers must be supported and helped by the organization they author code for. As software developers author code that makes up a web application, they need to embrace and practice a wide variety of secure coding techniques. The OWASP Top Ten Proactive Controls (2018) is an OWASP documentation project that lists critical security techniques that should be included in every software development project. This document was written by developers for developers to assist those new to secure development.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Bypassing iOS Security using Enterprise Provisioning Hooks and Enterprise Mobility Management &amp;lt;br /&amp;gt; (By: '''Georgia Weidman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This talk demonstrates how features Apple includes in their iOS ecosystem to support corporate enterprise provisioning and management can be used to exploit all iOS devices. We will cover the faculties that Apple includes to allow enterprises and mobile security vendors to remotely provision settings and load applications and how a malicious attacker could take advantage of these vectors.&lt;br /&gt;
We will discuss Configuration Profile options with security implications and using the Enterprise Development Program to bypass Apple’s anti-malware app controls. Though Apple considers this a “feature not a bug” and a phishing issue, no anti-phishing training readily available for either consumers or corporations specifically address these phishing attacks. However, according to the Verizon Breach Report over 90% of enterprise compromises came in through endpoints, largely from phishing.&lt;br /&gt;
Mobile devices open up a wide range of additional phishing options than the email scenarios. We will demonstrate how penetration testers and red teams can simulate these attacks to raise user awareness and perform impact analysis of a potential breach begun by a compromised iOS device.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Jim Manico is the founder of Manicode Security where he trains software developers on secure coding and security engineering. He is also an investor/advisor for KSOC, Nucleus Security, Signal Sciences, Secure Circle and BitDiscovery. Jim is a frequent speaker on secure software practices, is a member of the Java Champion community, and is the author of &amp;quot;Iron-Clad Java: Building Secure Web Applications&amp;quot; from Oracle Press. Jim also volunteers for the OWASP foundation as the project co-lead for the OWASP Application Security Verification Standard and the OWASP Proactive Controls. For more information, see http://www.linkedin.com/in/jmanico.&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Georgia Weidman is a serial entrepreneur, penetration tester, security researcher, speaker, trainer, and author. She is a member of the CyberWatch Center's National Visiting Committee, on the board of advisors at Cybrary, and an Adjunct Professor at UMUC and Tulane University. She is a New America Cybersecurity Policy Fellow. She has presented or conducted training around the world and is regularly featured internationally in print and on television. She authored Penetration Testing: A Hands-On Introduction to Hacking. Georgia founded the security consulting firm Bulb Security and was awarded a DARPA Cyber Fast Track grant for her work in mobile device security culminating in the release of the Smartphone Pentest Framework. She founded Shevirah whose products assess and manage the risk of mobile devices in the enterprise and is a graduate of the Mach37 cybersecurity accelerator. She was the 2015 Women’s Society of CyberJutsu Pentest Ninja. She holds a MS in computer science and CISSP, CEH, and OSCP certifications. &lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Cairo, Egypt (Hotel location will be updated) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253005</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=253005"/>
				<updated>2019-07-15T05:50:06Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP AppSec Africa  ===== &lt;br /&gt;
Event announcing pended on foundation review/approval &lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is planning to host AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=250362</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=250362"/>
				<updated>2019-04-20T07:57:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP AppSec Africa  ===== &lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is hosting AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, drop us an email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=250361</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=250361"/>
				<updated>2019-04-20T07:56:17Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP AppSec Africa  ===== &lt;br /&gt;
&lt;br /&gt;
'''Call For Event Volunteers'''&amp;lt;br /&amp;gt;&lt;br /&gt;
This year, OWASP Egypt is hosting AppSec Africa, the premier application security conference for African developers and security experts.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
AppSec Africa will provide attendees with insight into key application security topics and exposure to best practices in cybersecurity.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In OWASP we strongly believe in the power of the community and we rely on the contributions of enthusiastic and talented individuals across the world to advance the state of application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As such, we are calling for volunteers to participate in the preparation of the event. We need your support in the following areas:&amp;lt;br /&amp;gt;&lt;br /&gt;
1. Web/Mobile app development&amp;lt;br /&amp;gt;&lt;br /&gt;
2. Event facilitation (We will have number of external speakers)&amp;lt;br /&amp;gt;&lt;br /&gt;
3. Lab/Workshops setup/facilitation&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If you are interested in joining AppSec Africa team, reply to this email and tell us a little bit about yourself, your skills, and the area you would like to volunteer for.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Looking forward to hearing back from you.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Initial Planned Date:'''&amp;lt;br /&amp;gt; &lt;br /&gt;
21th of September 2019&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248590</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248590"/>
				<updated>2019-03-09T15:39:18Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''' and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Mohamed Talaat'''and '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Amr Elshamy''' and '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248584</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248584"/>
				<updated>2019-03-09T10:39:02Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: OWASP Top 10  - A1 and A2 '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The first day of the awareness program includes four sessions covering the first two of OWASP top 10 risks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248583</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248583"/>
				<updated>2019-03-09T10:35:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- &amp;quot;A1-Injection&amp;quot; Risk and Attack Demo [By: '''Mohamed Talaat''']&amp;lt;br /&amp;gt; 12:00 to 12:45&amp;lt;br /&amp;gt;&lt;br /&gt;
2- &amp;quot;A1-Injection&amp;quot; Attack Mitigations with Demo [By: '''Moustafa Gamal''']&amp;lt;br /&amp;gt; 12:45 to 13:30&amp;lt;br /&amp;gt;&lt;br /&gt;
3- &amp;quot;A2-Broken Authentication&amp;quot; Risk and Attack Demo [By: '''Amr Elshamy'''] &amp;lt;br /&amp;gt;13:30 to 14:15&amp;lt;br /&amp;gt;&lt;br /&gt;
4- &amp;quot;A2-Broken Authentication&amp;quot; Attack Mitigations with Demo [By: '''Mahmoud Ibrahim''']&amp;lt;br /&amp;gt; 14:15 to 15:00&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248327</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248327"/>
				<updated>2019-03-05T11:26:48Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
9 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks [By: '''TBD''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks [By: '''Mohamed Talaat''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations  [By: '''Mohamed Talaat''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions Coordinator: '''&amp;lt;br /&amp;gt;['''Mohamed Mashaly''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248326</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=248326"/>
				<updated>2019-03-05T11:15:55Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the forth year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://cit-fei.org/Upload_Admin_Entity_Media_Filename_9f864882903418a8979873ece72e79e8.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/BukF6C&amp;lt;br /&amp;gt;&lt;br /&gt;
Registration is totally free.&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2019 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
AppSec Lessons from Battlefield [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Mohamed_Alfateh&amp;diff=248325</id>
		<title>User:Mohamed Alfateh</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Mohamed_Alfateh&amp;diff=248325"/>
				<updated>2019-03-05T11:11:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mohamed Alfateh specialized in security auditing and Java /J2EE application security with experience in penetration testing and software security assessment. Mohamed has many contributions for OWASP, he leads the Cairo chapter and is a board member of OWASP Middle-East. Alfateh is the author for the new version of the application threat modeling cheat sheet. He is currently Sr. Consultant in ZISS team (ZINAD Information Security Services), holding GSSP-JAVA, GSNA, GSEC, ISO27001 LA and Lead SCADA Security Manager certificates.&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=246981</id>
		<title>Threat Modeling Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=246981"/>
				<updated>2019-02-01T12:30:35Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; __NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Cheatsheets-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
 __TOC__{{TOC hidden}}&lt;br /&gt;
''DRAFT CHEAT SHEET ''&lt;br /&gt;
= Introduction =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Objective of the Threat Modelling Control Cheat Sheet – To provide guidance to architects, designers and reviewers, on deriving threat models for applications.&lt;br /&gt;
&lt;br /&gt;
Audience: &lt;br /&gt;
&lt;br /&gt;
# Designers and Architects&lt;br /&gt;
# Assessors: Threat&amp;amp;nbsp;Modeling&amp;amp;nbsp;SMEs or Security&amp;amp;nbsp;Assessors&amp;amp;nbsp;who are responsible for analyzing the security of the entire applciations’ components.&lt;br /&gt;
&lt;br /&gt;
This cheat sheet provides guidance to assess existing apps as well as new apps. The instructions in here will help designer and architects address applications risks in an early stage of the development life cycle to help developers consider these risks while writing the code. It will also help assessors to look at risks from a comprehensive perspective. &lt;br /&gt;
&lt;br /&gt;
Following the guidance in this cheat sheet, the assessors will list all possible risks and then verifies whether there are enough security controls to protect against these risks. The assessor will then give better recommendations on how to mitigate these risks. It will help the assessor discover logical attacks. In general, the threat modelling will help designers, architects and assessors discover logical attacks. &lt;br /&gt;
&lt;br /&gt;
= Preparation =&lt;br /&gt;
== Understand Risk Management Basics in Context of Application Security ==&lt;br /&gt;
&lt;br /&gt;
Understand the Relation between Risk, Threats, and Vulnerabilities &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Understand Threat Modeling Terminologies ==&lt;br /&gt;
=== Asset, Threat Agent, Attack Surface, Likelihood, Impact, Control, Mitigation, Tractability Matrix ===&lt;br /&gt;
&lt;br /&gt;
Information Asset: is a body of knowledge that is organized and managed as a single entity. Like any other corporate&amp;amp;nbsp;asset, an organization's&amp;amp;nbsp;information assets have financial value.&lt;br /&gt;
&lt;br /&gt;
Threat Agent: The term&amp;amp;nbsp;Threat Agent&amp;amp;nbsp;is used to indicate an individual or group that can manifest athreat. It is fundamental to identify who would want to exploit the assets of a company, and how they might use them against the company.&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Attack Surface: The&amp;amp;nbsp;attack surface&amp;amp;nbsp;of a software environment is the sum of the different points (the &amp;quot;attack&amp;amp;nbsp;vectors&amp;quot;) where an unauthorized user (the &amp;quot;attacker&amp;quot;) can try to enter data to or extract data from an environment.&lt;br /&gt;
&lt;br /&gt;
Likelihood: Likelihood of threat event initiation or occurrence represents the degree to which a threat actor will carry out a threat. The likelihood of threat events resulting in adverse impacts estimates the possibility that a threat event would result in an actual outcome. The combined analysis of both threat assessment vectors impacts established an overall threat likelihood.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Impact: the damage potential, such as the number of components that are affected by a threat.&lt;br /&gt;
&lt;br /&gt;
Control: the safeguard or countermeasure to avoid, detect, counteract, or minimize security risks to information, computer systems, or other assets.&lt;br /&gt;
&lt;br /&gt;
Mitigation: A systematic reduction in the extent of exposure to a risk and/or the likelihood of its occurrence. &lt;br /&gt;
&lt;br /&gt;
Tractability Matrix: a grid that allows documentation and easy viewing of what is required for a system's security.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
== Define Objectives ==&lt;br /&gt;
&lt;br /&gt;
Before starting the threat modelling process; it is important to identify business objectives of the applications, and identify security &amp;amp; compliance requirements. This is very important to be defined in advance to help evaluating the impact of any vulnerability during the risk analysis process.&lt;br /&gt;
&lt;br /&gt;
= Identify Application Design =&lt;br /&gt;
&lt;br /&gt;
Understanding application design is a key activity to perform application threat modelling. It will enable the user of this cheat sheet to draw an accurate data flow diagram. Therefore, it will be easier to identify all possible risks. Moreover, the more the user of this cheat sheet understands application design, the better they will understand logical application attacks. The objective of the design document is to enumerate application components. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Review the Application Design Document ==&lt;br /&gt;
&lt;br /&gt;
If you are not performing threat modelling during the development (in the design phase) so you have to review the application design documents to understand the application structure and to help generating the data flow diagram. If there are no available design documents so you have to create one. Move to next section &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Create Design Documents ==&lt;br /&gt;
&lt;br /&gt;
There are many ways to generate design documents; the 4+1 view model is one of the matured approaches to build your design document. Reference to 4+1 view model of architecture: [http://ieeexplore.ieee.org/abstract/document/469759/?reload=true http://ieeexplore.ieee.org/abstract/document/469759/?reload=true] &lt;br /&gt;
&lt;br /&gt;
Please note that, the 4+1 is comprehensive, you may use any other design model during this phase.&lt;br /&gt;
&lt;br /&gt;
The following subsections show the details about 4+1 approach and how this could help in the threat modelling process:&lt;br /&gt;
&lt;br /&gt;
=== Logical View ===&lt;br /&gt;
&lt;br /&gt;
Create a logical map of the Target of Evaluation. &lt;br /&gt;
&lt;br /&gt;
'''Audience''': Designers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Functional Requirements: describes the design's object model. &lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Design model&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Programmers.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Software components: describes the layers and subsystems of the application.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Implementation model, components&lt;br /&gt;
&lt;br /&gt;
Please refer to the image in the appendix section for sample design for the implementation view. &lt;br /&gt;
&lt;br /&gt;
=== Process View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Integrators.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Non-functional requirements: describes the design's concurrency and synchronization aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''(no specific artifact).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Deployment View ===&lt;br /&gt;
&lt;br /&gt;
Create a physical map of the Target of Evaluation&lt;br /&gt;
&lt;br /&gt;
'''Audience''': Deployment managers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Topology: describes the mapping of the software onto the hardware and shows the system's distributed aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Deployment model.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Use-Case View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''all the stakeholders of the system, including the end-users.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''describes the set of scenarios and/or use cases that represent some significant, central functionality of the system.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Use-Case Model, Use-Case documents&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Decompose and Model the System =&lt;br /&gt;
&lt;br /&gt;
Gain an understanding of how the system works to perform a threat model, it is important to understand how the system works and interacts with its ecosystem. To start with creating a high-level information flow diagram, like the following:&lt;br /&gt;
&lt;br /&gt;
# Identify the trusted boundaries of your system / application / module / ecosystem that you may want to start off with.&lt;br /&gt;
# Add actors – internal and external&lt;br /&gt;
# Define internal trusted boundaries. These can be the different security zones that have been designed&lt;br /&gt;
# Relook at the actors you have identified in #2 for consistency&lt;br /&gt;
# Add information flows&lt;br /&gt;
# Identify the information elements and their classification as per your information classification policy&lt;br /&gt;
# Where possible add assets to the identified information flows.&lt;br /&gt;
&lt;br /&gt;
== Define and Evaluate Your Assets ==&lt;br /&gt;
&lt;br /&gt;
Assets involved in the information flow should be defined and evaluated according to their value of confidentiality, integrity and availability. &lt;br /&gt;
&lt;br /&gt;
=== Consider Data in Transit and Data at Rest ===&lt;br /&gt;
&lt;br /&gt;
Data protection in transit is the protection of this data while it’s traveling from network to network or being transferred from a local storage device to a cloud storage device – wherever data is moving, effective data protection measures for in transit data are critical as data is often considered less secure while in motion. &lt;br /&gt;
&lt;br /&gt;
While data at rest is sometimes considered to be less vulnerable than data in transit, attackers often find data at rest a more valuable target than data in motion. &lt;br /&gt;
&lt;br /&gt;
The risk profile for data in transit or data at rest depends on the security measures that are in place to secure data in either state. Protecting sensitive data both in transit and at rest is imperative for modern enterprises as attackers find increasingly innovative ways to compromise systems and steal data.&lt;br /&gt;
&lt;br /&gt;
== Create an Information Flow Diagram ==&lt;br /&gt;
=== Whiteboard Your Architecture ===&lt;br /&gt;
&lt;br /&gt;
It is important to whiteboard system architecture by showing the major constraints and decisions in order to frame and start conversations. The value is actually twofold. If the architecture cannot be white-boarded, then it suggests that it is not well understood. If a clear and concise whiteboard diagram can be provided, others will understand it and it will be easier to communicate details. &lt;br /&gt;
&lt;br /&gt;
=== Manage to Present your DFD in Context of MVC ===&lt;br /&gt;
&lt;br /&gt;
In this step Data Flow Diagram should be divided the in the context of Model, View, Controller (MVC).&lt;br /&gt;
&lt;br /&gt;
=== Use Tools to Draw your Diagram ===&lt;br /&gt;
&lt;br /&gt;
If you don’t like to manually draw your DFD; there are several tools available that could be used:&lt;br /&gt;
&lt;br /&gt;
==== Poirot ====&lt;br /&gt;
&lt;br /&gt;
The Poirot tool isolates and diagnoses defects through fault modelling and simulation. Along with a carefully selected partitioning strategy, functional and sequential test pattern applications show success with circuits having a high degree of observability.&lt;br /&gt;
&lt;br /&gt;
==== MS Threat modeling ====&lt;br /&gt;
&lt;br /&gt;
A tool that helps in finding threats in the design phase of software projects.&lt;br /&gt;
&lt;br /&gt;
== Define Data Flow over your DFD ==&lt;br /&gt;
&lt;br /&gt;
Define Data Flows over the organization Data Flow Diagram.&lt;br /&gt;
&lt;br /&gt;
== Define Trust Boundaries ==&lt;br /&gt;
&lt;br /&gt;
Define any distinct&amp;amp;nbsp;boundaries (External boundaries and Internal boundaries) within which a system&amp;amp;nbsp;trusts&amp;amp;nbsp;all sub-systems (including data).&lt;br /&gt;
&lt;br /&gt;
== Define Applications User Roles and Trust Levels ==&lt;br /&gt;
&lt;br /&gt;
Define access rights that the application will grant to external entities and internal entities.&lt;br /&gt;
&lt;br /&gt;
== Highlight Authorization per User Role Over the DFD ==&lt;br /&gt;
&lt;br /&gt;
Highlight Authorization per user role, for example, defining app users’ role, admins’ role, anonymous visitors’ role...etc.&lt;br /&gt;
&lt;br /&gt;
== Define Application Entry points ==&lt;br /&gt;
&lt;br /&gt;
Define the interfaces through which potential attackers can interact with the application or supply it with data.&lt;br /&gt;
&lt;br /&gt;
= Identify Threat Agents =&lt;br /&gt;
== Define all possible threats ==&lt;br /&gt;
&lt;br /&gt;
Identify Possible Attackers threat agents that could exist within the Target of Evaluation. Use Means, Motive, and Opportunities to understand Threats posed by Attackers. Then associate threat agents with system components they can directly interact with.&lt;br /&gt;
&lt;br /&gt;
Work on minimizing the number of threat agents by: &lt;br /&gt;
&lt;br /&gt;
* Treating them as equivalent classes. &lt;br /&gt;
&lt;br /&gt;
* Considering attacker’s motivation when evaluating likelihood.&lt;br /&gt;
* Consider insider Threats &lt;br /&gt;
&lt;br /&gt;
The user of this cheat can depend on the following list of risks and threat libraries sources to define the possible threats an application might be facing:&lt;br /&gt;
&lt;br /&gt;
# Risks with OWASP Top 10.&lt;br /&gt;
# Testing Procedure with OWASP ASVS.&lt;br /&gt;
# Risks with SANS Top 25.&lt;br /&gt;
# MS STRIDE.&lt;br /&gt;
&lt;br /&gt;
== Map Threat Agents to Application Entry Points ==&lt;br /&gt;
&lt;br /&gt;
Map threat agents to application entry point, whether it is a login process, a registration process or whatever it might be and consider insider Threats.&lt;br /&gt;
&lt;br /&gt;
== Draw Attack Vectors and Attacks Tree ==&lt;br /&gt;
&lt;br /&gt;
During this phase conduct the following activities: &lt;br /&gt;
&lt;br /&gt;
* Draw attack vectors and attacks tree.&lt;br /&gt;
* Identify Use Cases/Abuse Cases. &lt;br /&gt;
* Re-Define attack vectors to consider multi-step attacks.&lt;br /&gt;
&lt;br /&gt;
== Mapping Abuse Cases to Use Cases ==&lt;br /&gt;
== Re-Define Attack Vectors ==&lt;br /&gt;
&lt;br /&gt;
In most cases after defining the attack vectors, the compromised user role could lead to further attacks into the application. For example, assuming that an internet banking user credentials could be compromised, the user of this cheat sheet has to then redefine the attack vectors that could result from compromising the user’s credentials and so on. &lt;br /&gt;
&lt;br /&gt;
= Write your Threat Traceability Matrix =&lt;br /&gt;
== Define the Impact and Probability for Each Threat ==&lt;br /&gt;
&lt;br /&gt;
Enumerate Attacks posed by most dangerous attacker in designated areas of the logical and physical maps of the target of evaluation.&lt;br /&gt;
&lt;br /&gt;
Assume the attacker has a zero day, because he does. In this methodology, we assume compromise; because a zero day will exist or already does exist (even if we don't know about it). This is about what can be done by skilled attackers, with much more time, money, motive and opportunity than we have.&lt;br /&gt;
&lt;br /&gt;
Use risk management methodology to determine the risk behind the threat&lt;br /&gt;
&lt;br /&gt;
Create risks in risk log for every identified threat or attack to any assets. A risk assessment methodology is followed in order to identify the risk level for each vulnerability and hence for each server. &lt;br /&gt;
&lt;br /&gt;
Here we will highlight two risk methodology that could be used:&lt;br /&gt;
&lt;br /&gt;
=== DREAD ===&lt;br /&gt;
&lt;br /&gt;
DREAD, is about evaluating each existing vulnerability using a mathematical formula to retrieve the vulnerability’s corresponding risk. The '''DREAD''' formula is divided into 5 main categories:&lt;br /&gt;
&lt;br /&gt;
* '''D'''amage - how bad would an attack be?&lt;br /&gt;
* '''R'''eproducibility - how easy it is to reproduce the attack?&lt;br /&gt;
* '''E'''xploitability - how much work is it to launch the attack?&lt;br /&gt;
* '''A'''ffected users - how many people will be impacted?&lt;br /&gt;
* '''D'''iscoverability - how easy it is to discover the threat?&lt;br /&gt;
&lt;br /&gt;
'''DREAD''' formula is: &lt;br /&gt;
&lt;br /&gt;
Risk Value = (Damage + Affected users) x (Reproducibility + Exploitability + Discoverability).&lt;br /&gt;
&lt;br /&gt;
Then the risk level is determined using defined thresholds below.&lt;br /&gt;
&lt;br /&gt;
=== PASTA ===&lt;br /&gt;
&lt;br /&gt;
PASTA, Attack Simulation &amp;amp; Threat Analysis (PASTA) is a complete methodology to perform application threat modleing. PASTA introduces a risk-centric methodology aimed at applying security countermeasures that are commensurate to the possible impact that could be sustained from defined threat models, vulnerabilities, weaknesses, and attack patterns. &lt;br /&gt;
&lt;br /&gt;
PASTA introduces a complete risk analysis and evaluation procedures that you can follow to evaluate the risk for each of the identified threat. The main difference in using PASTA Approach is that you should evaluate the impact early on in the analysis phase instead of addressing the impact at the step of evaluating the risk.&lt;br /&gt;
&lt;br /&gt;
The idea behind addressing the impact earlier in PASTA approach is that the audience that knows impact knows the consequences of product or use case failures more than participants in the threat analysis phase.&lt;br /&gt;
&lt;br /&gt;
Application security risk assessments are not enough because they&amp;amp;nbsp;are very binary and leverage a control framework basis for denoting risks. It is recommended to contextually look at threats, impacts, probability, effectiveness of countermeasures that may be present. R=(T*V*P*I)/Countermeasures&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more details about PASTA:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/a/aa/AppSecEU2012_PASTA.pdf &lt;br /&gt;
&lt;br /&gt;
== Rank Risks ==&lt;br /&gt;
&lt;br /&gt;
Using risk matrix rank risks from most severe to least severe based on Means, Motive &amp;amp; Opportunity. Below is sample risk matrix table, depending on your risk approach you can define deferent risk ranking matrix:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 1 to 12 [Risk Level: Notice]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 13 to 18 [Risk Level: Low]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 19 to 36 [Risk Level: Meduim]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 37 to 54 [Risk Level: High]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Determine Countermeasures and Mitigation. =&lt;br /&gt;
&lt;br /&gt;
Identify risk owners and agree on risk mitigation with risk owners and stakeholders. Provide the needed controls in forms of code upgrades and configuration updates to reduce risks to acceptable levels. &lt;br /&gt;
&lt;br /&gt;
== Identify Risk Owners ==&lt;br /&gt;
&lt;br /&gt;
For the assessors: After defining and analysing the risks, the assessor should be working on the mitigation plan by firstly identifying risk owners which is the personnel that is responsible for mitigating the risk. i.e. one of the information security team or the development team. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For the designers or the architects: they should assign the risk mitigation to the development team to consider it while building the application. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Agree on Risk Mitigation With Risk Owners and Stakeholders ==&lt;br /&gt;
== Build Your Risk Treatment Strategy ==&lt;br /&gt;
&lt;br /&gt;
* Reduce: building controls if the form of code upgrades, confirming a specific design for the application or building a specific configuration during the deployment phase to make sure that application risk is reduced. &lt;br /&gt;
* Transfer: For a specific component in the application the risk can be transferred to an outsourced third party to develop that component and making sure that the third party is doing the right testing for the component; or during the deployment phase, outsourcing a third party to do the deployment and transferring that risk to that third party. &lt;br /&gt;
* Avoid: an example of avoiding the risk is disabling a specific function in the application that is the source for that risk. &lt;br /&gt;
* Accept: if the risk is within acceptable criteria set earlier, in that case the designer risk owner can accept that risk. &lt;br /&gt;
&lt;br /&gt;
For the assessor this is considered that last step in the assessment process. The following steps should be conducted by the risk owner, however, the assessor shall engage in 6.5 (Testing risk treatment) to verify the remediation. &lt;br /&gt;
&lt;br /&gt;
== Select Appropriate Controls to Mitigate the Risk ==&lt;br /&gt;
&lt;br /&gt;
Selecting one of the controls to reduce the risk, either by upgrading the code, or building a specific configuration during the deployment phase and so on. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Risk Treatment to Verify Remediation ==&lt;br /&gt;
&lt;br /&gt;
Mitigation controls will not vanish the risk completely, rather, it would just reduce the risk. In this case, the user of this cheat sheet should measure the value of the risk after applying the mitigation controls. The value of the risk should be reduced to the acceptable criteria set earlier. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Reduce Risk in Risk Log for Verified Treated Risk ==&lt;br /&gt;
&lt;br /&gt;
After applying the mitigation and measuring the new risk value, the user of this cheat sheet should update the risk log to verify that risk has been reduced. &lt;br /&gt;
&lt;br /&gt;
== Periodically Retest Risk ==&lt;br /&gt;
&lt;br /&gt;
= Appendix =&lt;br /&gt;
'' Sample Design for Implementation View in 4+1 Model  ''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors and Primary Editors  ==&lt;br /&gt;
&lt;br /&gt;
Mohamed Alfateh &lt;br /&gt;
== Project Supporters  ==&lt;br /&gt;
Ahmed Kanoma&lt;br /&gt;
&lt;br /&gt;
== Other Cheatsheets ==&lt;br /&gt;
&lt;br /&gt;
{{Cheatsheet_Navigation_Body}}&lt;br /&gt;
[[Category:Cheatsheets]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=246980</id>
		<title>Threat Modeling Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=246980"/>
				<updated>2019-02-01T12:27:49Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; __NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Cheatsheets-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
 __TOC__{{TOC hidden}}&lt;br /&gt;
''DRAFT CHEAT SHEET ''&lt;br /&gt;
= Introduction =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Objective of the Threat Modelling Control Cheat Sheet – To provide guidance to architects, designers and reviewers, on deriving threat models for applications.&lt;br /&gt;
&lt;br /&gt;
Audience: &lt;br /&gt;
&lt;br /&gt;
# Designers and Architects&lt;br /&gt;
# Assessors: Threat&amp;amp;nbsp;Modeling&amp;amp;nbsp;SMEs or Security&amp;amp;nbsp;Assessors&amp;amp;nbsp;who are responsible for analyzing the security of the entire applciations’ components.&lt;br /&gt;
&lt;br /&gt;
This cheat sheet provides guidance to assess existing apps as well as new apps. The instructions in here will help designer and architects address applications risks in an early stage of the development life cycle to help developers consider these risks while writing the code. It will also help assessors to look at risks from a comprehensive perspective. &lt;br /&gt;
&lt;br /&gt;
Following the guidance in this cheat sheet, the assessors will list all possible risks and then verifies whether there are enough security controls to protect against these risks. The assessor will then give better recommendations on how to mitigate these risks. It will help the assessor discover logical attacks. In general, the threat modelling will help designers, architects and assessors discover logical attacks. &lt;br /&gt;
&lt;br /&gt;
= Preparation =&lt;br /&gt;
== Understand Risk Management Basics in Context of Application Security ==&lt;br /&gt;
&lt;br /&gt;
Understand the Relation between Risk, Threats, and Vulnerabilities &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Understand Threat Modeling Terminologies ==&lt;br /&gt;
=== Asset, Threat Agent, Attack Surface, Likelihood, Impact, Control, Mitigation, Tractability Matrix ===&lt;br /&gt;
&lt;br /&gt;
Information Asset: is a body of knowledge that is organized and managed as a single entity. Like any other corporate&amp;amp;nbsp;asset, an organization's&amp;amp;nbsp;information assets have financial value.&lt;br /&gt;
&lt;br /&gt;
Threat Agent: The term&amp;amp;nbsp;Threat Agent&amp;amp;nbsp;is used to indicate an individual or group that can manifest athreat. It is fundamental to identify who would want to exploit the assets of a company, and how they might use them against the company.&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Attack Surface: The&amp;amp;nbsp;attack surface&amp;amp;nbsp;of a software environment is the sum of the different points (the &amp;quot;attack&amp;amp;nbsp;vectors&amp;quot;) where an unauthorized user (the &amp;quot;attacker&amp;quot;) can try to enter data to or extract data from an environment.&lt;br /&gt;
&lt;br /&gt;
Likelihood: Likelihood of threat event initiation or occurrence represents the degree to which a threat actor will carry out a threat. The likelihood of threat events resulting in adverse impacts estimates the possibility that a threat event would result in an actual outcome. The combined analysis of both threat assessment vectors impacts established an overall threat likelihood.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Impact: the damage potential, such as the number of components that are affected by a threat.&lt;br /&gt;
&lt;br /&gt;
Control: the safeguard or countermeasure to avoid, detect, counteract, or minimize security risks to information, computer systems, or other assets.&lt;br /&gt;
&lt;br /&gt;
Mitigation: A systematic reduction in the extent of exposure to a risk and/or the likelihood of its occurrence. &lt;br /&gt;
&lt;br /&gt;
Tractability Matrix: a grid that allows documentation and easy viewing of what is required for a system's security.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
== Define Objectives ==&lt;br /&gt;
&lt;br /&gt;
Before starting the threat modelling process; it is important to identify business objectives of the applications, and identify security &amp;amp; compliance requirements. This is very important to be defined in advance to help evaluating the impact of any vulnerability during the risk analysis process.&lt;br /&gt;
&lt;br /&gt;
= Identify Application Design =&lt;br /&gt;
&lt;br /&gt;
Understanding application design is a key activity to perform application threat modelling. It will enable the user of this cheat sheet to draw an accurate data flow diagram. Therefore, it will be easier to identify all possible risks. Moreover, the more the user of this cheat sheet understands application design, the better they will understand logical application attacks. The objective of the design document is to enumerate application components. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Review the Application Design Document ==&lt;br /&gt;
&lt;br /&gt;
If you are not performing threat modelling during the development (in the design phase) so you have to review the application design documents to understand the application structure and to help generating the data flow diagram. If there are no available design documents so you have to create one. Move to next section &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Create Design Documents ==&lt;br /&gt;
&lt;br /&gt;
There are many ways to generate design documents; the 4+1 view model is one of the matured approaches to build your design document. Reference to 4+1 view model of architecture: [http://ieeexplore.ieee.org/abstract/document/469759/?reload=true http://ieeexplore.ieee.org/abstract/document/469759/?reload=true] &lt;br /&gt;
&lt;br /&gt;
Please note that, the 4+1 is comprehensive, you may use any other design model during this phase.&lt;br /&gt;
&lt;br /&gt;
The following subsections show the details about 4+1 approach and how this could help in the threat modelling process:&lt;br /&gt;
&lt;br /&gt;
=== Logical View ===&lt;br /&gt;
&lt;br /&gt;
Create a logical map of the Target of Evaluation. &lt;br /&gt;
&lt;br /&gt;
'''Audience''': Designers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Functional Requirements: describes the design's object model. &lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Design model&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Programmers.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Software components: describes the layers and subsystems of the application.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Implementation model, components&lt;br /&gt;
&lt;br /&gt;
Please refer to the image in the appendix section for sample design for the implementation view. &lt;br /&gt;
&lt;br /&gt;
=== Process View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Integrators.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Non-functional requirements: describes the design's concurrency and synchronization aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''(no specific artifact).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Deployment View ===&lt;br /&gt;
&lt;br /&gt;
Create a physical map of the Target of Evaluation&lt;br /&gt;
&lt;br /&gt;
'''Audience''': Deployment managers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Topology: describes the mapping of the software onto the hardware and shows the system's distributed aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Deployment model.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Use-Case View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''all the stakeholders of the system, including the end-users.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''describes the set of scenarios and/or use cases that represent some significant, central functionality of the system.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Use-Case Model, Use-Case documents&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Decompose and Model the System =&lt;br /&gt;
&lt;br /&gt;
Gain an understanding of how the system works to perform a threat model, it is important to understand how the system works and interacts with its ecosystem. To start with creating a high-level information flow diagram, like the following:&lt;br /&gt;
&lt;br /&gt;
# Identify the trusted boundaries of your system / application / module / ecosystem that you may want to start off with.&lt;br /&gt;
# Add actors – internal and external&lt;br /&gt;
# Define internal trusted boundaries. These can be the different security zones that have been designed&lt;br /&gt;
# Relook at the actors you have identified in #2 for consistency&lt;br /&gt;
# Add information flows&lt;br /&gt;
# Identify the information elements and their classification as per your information classification policy&lt;br /&gt;
# Where possible add assets to the identified information flows.&lt;br /&gt;
&lt;br /&gt;
== Define and Evaluate your Assets ==&lt;br /&gt;
&lt;br /&gt;
Assets involved in the information flow should be defined and evaluated according to their value of confidentiality, integrity and availability. &lt;br /&gt;
&lt;br /&gt;
=== Consider Data in transit and Data at rest ===&lt;br /&gt;
&lt;br /&gt;
Data protection in transit is the protection of this data while it’s traveling from network to network or being transferred from a local storage device to a cloud storage device – wherever data is moving, effective data protection measures for in transit data are critical as data is often considered less secure while in motion. &lt;br /&gt;
&lt;br /&gt;
While data at rest is sometimes considered to be less vulnerable than data in transit, attackers often find data at rest a more valuable target than data in motion. &lt;br /&gt;
&lt;br /&gt;
The risk profile for data in transit or data at rest depends on the security measures that are in place to secure data in either state. Protecting sensitive data both in transit and at rest is imperative for modern enterprises as attackers find increasingly innovative ways to compromise systems and steal data.&lt;br /&gt;
&lt;br /&gt;
== Create an information flow diagram ==&lt;br /&gt;
=== Whiteboard Your Architecture ===&lt;br /&gt;
&lt;br /&gt;
It is important to whiteboard system architecture by showing the major constraints and decisions in order to frame and start conversations. The value is actually twofold. If the architecture cannot be white-boarded, then it suggests that it is not well understood. If a clear and concise whiteboard diagram can be provided, others will understand it and it will be easier to communicate details. &lt;br /&gt;
&lt;br /&gt;
=== Manage to Present your DFD in Context of MVC ===&lt;br /&gt;
&lt;br /&gt;
In this step Data Flow Diagram should be divided the in the context of Model, View, Controller (MVC).&lt;br /&gt;
&lt;br /&gt;
=== Use Tools to Draw your Diagram ===&lt;br /&gt;
&lt;br /&gt;
If you don’t like to manually draw your DFD; there are several tools available that could be used:&lt;br /&gt;
&lt;br /&gt;
==== Poirot ====&lt;br /&gt;
&lt;br /&gt;
The Poirot tool isolates and diagnoses defects through fault modelling and simulation. Along with a carefully selected partitioning strategy, functional and sequential test pattern applications show success with circuits having a high degree of observability.&lt;br /&gt;
&lt;br /&gt;
==== MS Threat modeling ====&lt;br /&gt;
&lt;br /&gt;
A tool that helps in finding threats in the design phase of software projects.&lt;br /&gt;
&lt;br /&gt;
== Define Data Flow over your DFD ==&lt;br /&gt;
&lt;br /&gt;
Define Data Flows over the organization Data Flow Diagram.&lt;br /&gt;
&lt;br /&gt;
== Define Trust Boundaries ==&lt;br /&gt;
&lt;br /&gt;
Define any distinct&amp;amp;nbsp;boundaries (External boundaries and Internal boundaries) within which a system&amp;amp;nbsp;trusts&amp;amp;nbsp;all sub-systems (including data).&lt;br /&gt;
&lt;br /&gt;
== Define Applications User Roles and Trust Levels ==&lt;br /&gt;
&lt;br /&gt;
Define access rights that the application will grant to external entities and internal entities.&lt;br /&gt;
&lt;br /&gt;
== Highlight Authorization per User Role Over the DFD ==&lt;br /&gt;
&lt;br /&gt;
Highlight Authorization per user role, for example, defining app users’ role, admins’ role, anonymous visitors’ role...etc.&lt;br /&gt;
&lt;br /&gt;
== Define Application Entry points ==&lt;br /&gt;
&lt;br /&gt;
Define the interfaces through which potential attackers can interact with the application or supply it with data.&lt;br /&gt;
&lt;br /&gt;
= Identify Threat Agents =&lt;br /&gt;
== Define all possible threats ==&lt;br /&gt;
&lt;br /&gt;
Identify Possible Attackers threat agents that could exist within the Target of Evaluation. Use Means, Motive, and Opportunities to understand Threats posed by Attackers. Then associate threat agents with system components they can directly interact with.&lt;br /&gt;
&lt;br /&gt;
Work on minimizing the number of threat agents by: &lt;br /&gt;
&lt;br /&gt;
* Treating them as equivalent classes. &lt;br /&gt;
&lt;br /&gt;
* Considering attacker’s motivation when evaluating likelihood.&lt;br /&gt;
* Consider insider Threats &lt;br /&gt;
&lt;br /&gt;
The user of this cheat can depend on the following list of risks and threat libraries sources to define the possible threats an application might be facing:&lt;br /&gt;
&lt;br /&gt;
# Risks with OWASP Top 10.&lt;br /&gt;
# Testing Procedure with OWASP ASVS.&lt;br /&gt;
# Risks with SANS Top 25.&lt;br /&gt;
# MS STRIDE.&lt;br /&gt;
&lt;br /&gt;
== Map Threat Agents to Application Entry Points ==&lt;br /&gt;
&lt;br /&gt;
Map threat agents to application entry point, whether it is a login process, a registration process or whatever it might be and consider insider Threats.&lt;br /&gt;
&lt;br /&gt;
== Draw Attack Vectors and Attacks Tree ==&lt;br /&gt;
&lt;br /&gt;
During this phase conduct the following activities: &lt;br /&gt;
&lt;br /&gt;
* Draw attack vectors and attacks tree.&lt;br /&gt;
* Identify Use Cases/Abuse Cases. &lt;br /&gt;
* Re-Define attack vectors to consider multi-step attacks.&lt;br /&gt;
&lt;br /&gt;
== Mapping Abuse Cases to Use Cases ==&lt;br /&gt;
== Re-Define Attack Vectors ==&lt;br /&gt;
&lt;br /&gt;
In most cases after defining the attack vectors, the compromised user role could lead to further attacks into the application. For example, assuming that an internet banking user credentials could be compromised, the user of this cheat sheet has to then redefine the attack vectors that could result from compromising the user’s credentials and so on. &lt;br /&gt;
&lt;br /&gt;
= Write your Threat Traceability Matrix =&lt;br /&gt;
== Define the Impact and Probability for Each Threat ==&lt;br /&gt;
&lt;br /&gt;
Enumerate Attacks posed by most dangerous attacker in designated areas of the logical and physical maps of the target of evaluation.&lt;br /&gt;
&lt;br /&gt;
Assume the attacker has a zero day, because he does. In this methodology, we assume compromise; because a zero day will exist or already does exist (even if we don't know about it). This is about what can be done by skilled attackers, with much more time, money, motive and opportunity than we have.&lt;br /&gt;
&lt;br /&gt;
Use risk management methodology to determine the risk behind the threat&lt;br /&gt;
&lt;br /&gt;
Create risks in risk log for every identified threat or attack to any assets. A risk assessment methodology is followed in order to identify the risk level for each vulnerability and hence for each server. &lt;br /&gt;
&lt;br /&gt;
Here we will highlight two risk methodology that could be used:&lt;br /&gt;
&lt;br /&gt;
=== DREAD ===&lt;br /&gt;
&lt;br /&gt;
DREAD, is about evaluating each existing vulnerability using a mathematical formula to retrieve the vulnerability’s corresponding risk. The '''DREAD''' formula is divided into 5 main categories:&lt;br /&gt;
&lt;br /&gt;
* '''D'''amage - how bad would an attack be?&lt;br /&gt;
* '''R'''eproducibility - how easy it is to reproduce the attack?&lt;br /&gt;
* '''E'''xploitability - how much work is it to launch the attack?&lt;br /&gt;
* '''A'''ffected users - how many people will be impacted?&lt;br /&gt;
* '''D'''iscoverability - how easy it is to discover the threat?&lt;br /&gt;
&lt;br /&gt;
'''DREAD''' formula is: &lt;br /&gt;
&lt;br /&gt;
Risk Value = (Damage + Affected users) x (Reproducibility + Exploitability + Discoverability).&lt;br /&gt;
&lt;br /&gt;
Then the risk level is determined using defined thresholds below.&lt;br /&gt;
&lt;br /&gt;
=== PASTA ===&lt;br /&gt;
&lt;br /&gt;
PASTA, Attack Simulation &amp;amp; Threat Analysis (PASTA) is a complete methodology to perform application threat modleing. PASTA introduces a risk-centric methodology aimed at applying security countermeasures that are commensurate to the possible impact that could be sustained from defined threat models, vulnerabilities, weaknesses, and attack patterns. &lt;br /&gt;
&lt;br /&gt;
PASTA introduces a complete risk analysis and evaluation procedures that you can follow to evaluate the risk for each of the identified threat. The main difference in using PASTA Approach is that you should evaluate the impact early on in the analysis phase instead of addressing the impact at the step of evaluating the risk.&lt;br /&gt;
&lt;br /&gt;
The idea behind addressing the impact earlier in PASTA approach is that the audience that knows impact knows the consequences of product or use case failures more than participants in the threat analysis phase.&lt;br /&gt;
&lt;br /&gt;
Application security risk assessments are not enough because they&amp;amp;nbsp;are very binary and leverage a control framework basis for denoting risks. It is recommended to contextually look at threats, impacts, probability, effectiveness of countermeasures that may be present. R=(T*V*P*I)/Countermeasures&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more details about PASTA:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/a/aa/AppSecEU2012_PASTA.pdf &lt;br /&gt;
&lt;br /&gt;
== Rank Risks ==&lt;br /&gt;
&lt;br /&gt;
Using risk matrix rank risks from most severe to least severe based on Means, Motive &amp;amp; Opportunity. Below is sample risk matrix table, depending on your risk approach you can define deferent risk ranking matrix:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 1 to 12 [Risk Level: Notice]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 13 to 18 [Risk Level: Low]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 19 to 36 [Risk Level: Meduim]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 37 to 54 [Risk Level: High]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Determine Countermeasures and Mitigation. =&lt;br /&gt;
&lt;br /&gt;
Identify risk owners and agree on risk mitigation with risk owners and stakeholders. Provide the needed controls in forms of code upgrades and configuration updates to reduce risks to acceptable levels. &lt;br /&gt;
&lt;br /&gt;
== Identify Risk Owners ==&lt;br /&gt;
&lt;br /&gt;
For the assessors: After defining and analysing the risks, the assessor should be working on the mitigation plan by firstly identifying risk owners which is the personnel that is responsible for mitigating the risk. i.e. one of the information security team or the development team. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For the designers or the architects: they should assign the risk mitigation to the development team to consider it while building the application. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Agree on Risk Mitigation With Risk Owners and Stakeholders ==&lt;br /&gt;
== Build Your Risk Treatment Strategy ==&lt;br /&gt;
&lt;br /&gt;
* Reduce: building controls if the form of code upgrades, confirming a specific design for the application or building a specific configuration during the deployment phase to make sure that application risk is reduced. &lt;br /&gt;
* Transfer: For a specific component in the application the risk can be transferred to an outsourced third party to develop that component and making sure that the third party is doing the right testing for the component; or during the deployment phase, outsourcing a third party to do the deployment and transferring that risk to that third party. &lt;br /&gt;
* Avoid: an example of avoiding the risk is disabling a specific function in the application that is the source for that risk. &lt;br /&gt;
* Accept: if the risk is within acceptable criteria set earlier, in that case the designer risk owner can accept that risk. &lt;br /&gt;
&lt;br /&gt;
For the assessor this is considered that last step in the assessment process. The following steps should be conducted by the risk owner, however, the assessor shall engage in 6.5 (Testing risk treatment) to verify the remediation. &lt;br /&gt;
&lt;br /&gt;
== Select Appropriate Controls to Mitigate the Risk ==&lt;br /&gt;
&lt;br /&gt;
Selecting one of the controls to reduce the risk, either by upgrading the code, or building a specific configuration during the deployment phase and so on. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Risk Treatment to Verify Remediation ==&lt;br /&gt;
&lt;br /&gt;
Mitigation controls will not vanish the risk completely, rather, it would just reduce the risk. In this case, the user of this cheat sheet should measure the value of the risk after applying the mitigation controls. The value of the risk should be reduced to the acceptable criteria set earlier. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Reduce Risk in Risk Log for Verified Treated Risk ==&lt;br /&gt;
&lt;br /&gt;
After applying the mitigation and measuring the new risk value, the user of this cheat sheet should update the risk log to verify that risk has been reduced. &lt;br /&gt;
&lt;br /&gt;
== Periodically Retest Risk ==&lt;br /&gt;
&lt;br /&gt;
= Appendix =&lt;br /&gt;
'' Sample Design for Implementation View in 4+1 Model  ''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors and Primary Editors  ==&lt;br /&gt;
&lt;br /&gt;
Mohamed Alfateh &lt;br /&gt;
== Project Supporters  ==&lt;br /&gt;
Ahmed Kanoma&lt;br /&gt;
&lt;br /&gt;
== Other Cheatsheets ==&lt;br /&gt;
&lt;br /&gt;
{{Cheatsheet_Navigation_Body}}&lt;br /&gt;
[[Category:Cheatsheets]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=246979</id>
		<title>Threat Modeling Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=246979"/>
				<updated>2019-02-01T12:24:25Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; __NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Cheatsheets-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
 __TOC__{{TOC hidden}}&lt;br /&gt;
''DRAFT CHEAT SHEET ''&lt;br /&gt;
= Introduction =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Objective of the Threat Modelling Control Cheat Sheet – To provide guidance to architects, designers and reviewers, on deriving threat models for applications.&lt;br /&gt;
&lt;br /&gt;
Audience: &lt;br /&gt;
&lt;br /&gt;
# Designers and Architects&lt;br /&gt;
# Assessors: Threat&amp;amp;nbsp;Modeling&amp;amp;nbsp;SMEs or Security&amp;amp;nbsp;Assessors&amp;amp;nbsp;who are responsible for analyzing the security of the entire applciations’ components.&lt;br /&gt;
&lt;br /&gt;
This cheat sheet provides guidance to assess existing apps as well as new apps. The instructions in here will help designer and architects address applications risks in an early stage of the development life cycle to help developers consider these risks while writing the code. It will also help assessors to look at risks from a comprehensive perspective. &lt;br /&gt;
&lt;br /&gt;
Following the guidance in this cheat sheet, the assessors will list all possible risks and then verifies whether there are enough security controls to protect against these risks. The assessor will then give better recommendations on how to mitigate these risks. It will help the assessor discover logical attacks. In general, the threat modelling will help designers, architects and assessors discover logical attacks. &lt;br /&gt;
&lt;br /&gt;
= Preparation =&lt;br /&gt;
== Understand Risk Management Basics in Context of Application Security ==&lt;br /&gt;
&lt;br /&gt;
Understand the Relation between Risk, Threats, and Vulnerabilities &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Understand Threat Modeling Terminologies ==&lt;br /&gt;
=== Asset, Threat Agent, Attack Surface, Likelihood, Impact, Control, Mitigation, Tractability Matrix ===&lt;br /&gt;
&lt;br /&gt;
Information Asset: is a body of knowledge that is organized and managed as a single entity. Like any other corporate&amp;amp;nbsp;asset, an organization's&amp;amp;nbsp;information assets have financial value.&lt;br /&gt;
&lt;br /&gt;
Threat Agent: The term&amp;amp;nbsp;Threat Agent&amp;amp;nbsp;is used to indicate an individual or group that can manifest athreat. It is fundamental to identify who would want to exploit the assets of a company, and how they might use them against the company.&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Attack Surface: The&amp;amp;nbsp;attack surface&amp;amp;nbsp;of a software environment is the sum of the different points (the &amp;quot;attack&amp;amp;nbsp;vectors&amp;quot;) where an unauthorized user (the &amp;quot;attacker&amp;quot;) can try to enter data to or extract data from an environment.&lt;br /&gt;
&lt;br /&gt;
Likelihood: Likelihood of threat event initiation or occurrence represents the degree to which a threat actor will carry out a threat. The likelihood of threat events resulting in adverse impacts estimates the possibility that a threat event would result in an actual outcome. The combined analysis of both threat assessment vectors impacts established an overall threat likelihood.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Impact: the damage potential, such as the number of components that are affected by a threat.&lt;br /&gt;
&lt;br /&gt;
Control: the safeguard or countermeasure to avoid, detect, counteract, or minimize security risks to information, computer systems, or other assets.&lt;br /&gt;
&lt;br /&gt;
Mitigation: A systematic reduction in the extent of exposure to a risk and/or the likelihood of its occurrence. &lt;br /&gt;
&lt;br /&gt;
Tractability Matrix: a grid that allows documentation and easy viewing of what is required for a system's security.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
== Define Objectives ==&lt;br /&gt;
&lt;br /&gt;
Before starting the threat modelling process; it is important to identify business objectives of the applications, and identify security &amp;amp; compliance requirements. This is very important to be defined in advance to help evaluating the impact of any vulnerability during the risk analysis process.&lt;br /&gt;
&lt;br /&gt;
= Identify application design =&lt;br /&gt;
&lt;br /&gt;
Understanding application design is a key activity to perform application threat modelling. It will enable the user of this cheat sheet to draw an accurate data flow diagram. Therefore, it will be easier to identify all possible risks. Moreover, the more the user of this cheat sheet understands application design, the better they will understand logical application attacks. The objective of the design document is to enumerate application components. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Review the application design document ==&lt;br /&gt;
&lt;br /&gt;
If you are not performing threat modelling during the development (in the design phase) so you have to review the application design documents to understand the application structure and to help generating the data flow diagram. If there are no available design documents so you have to create one. Move to next section &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Create design documents ==&lt;br /&gt;
&lt;br /&gt;
There are many ways to generate design documents; the 4+1 view model is one of the matured approaches to build your design document. Reference to 4+1 view model of architecture: [http://ieeexplore.ieee.org/abstract/document/469759/?reload=true http://ieeexplore.ieee.org/abstract/document/469759/?reload=true] &lt;br /&gt;
&lt;br /&gt;
Please note that, the 4+1 is comprehensive, you may use any other design model during this phase.&lt;br /&gt;
&lt;br /&gt;
The following subsections show the details about 4+1 approach and how this could help in the threat modelling process:&lt;br /&gt;
&lt;br /&gt;
=== Logical View ===&lt;br /&gt;
&lt;br /&gt;
Create a logical map of the Target of Evaluation. &lt;br /&gt;
&lt;br /&gt;
'''Audience''': Designers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Functional Requirements: describes the design's object model. &lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Design model&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Programmers.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Software components: describes the layers and subsystems of the application.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Implementation model, components&lt;br /&gt;
&lt;br /&gt;
Please refer to the image in the appendix section for sample design for the implementation view. &lt;br /&gt;
&lt;br /&gt;
=== Process View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Integrators.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Non-functional requirements: describes the design's concurrency and synchronization aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''(no specific artifact).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Deployment View ===&lt;br /&gt;
&lt;br /&gt;
Create a physical map of the Target of Evaluation&lt;br /&gt;
&lt;br /&gt;
'''Audience''': Deployment managers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Topology: describes the mapping of the software onto the hardware and shows the system's distributed aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Deployment model.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Use-Case View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''all the stakeholders of the system, including the end-users.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''describes the set of scenarios and/or use cases that represent some significant, central functionality of the system.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Use-Case Model, Use-Case documents&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Decompose and Model the System =&lt;br /&gt;
&lt;br /&gt;
Gain an understanding of how the system works to perform a threat model, it is important to understand how the system works and interacts with its ecosystem. To start with creating a high-level information flow diagram, like the following:&lt;br /&gt;
&lt;br /&gt;
# Identify the trusted boundaries of your system / application / module / ecosystem that you may want to start off with.&lt;br /&gt;
# Add actors – internal and external&lt;br /&gt;
# Define internal trusted boundaries. These can be the different security zones that have been designed&lt;br /&gt;
# Relook at the actors you have identified in #2 for consistency&lt;br /&gt;
# Add information flows&lt;br /&gt;
# Identify the information elements and their classification as per your information classification policy&lt;br /&gt;
# Where possible add assets to the identified information flows.&lt;br /&gt;
&lt;br /&gt;
== Define and Evaluate your Assets ==&lt;br /&gt;
&lt;br /&gt;
Assets involved in the information flow should be defined and evaluated according to their value of confidentiality, integrity and availability. &lt;br /&gt;
&lt;br /&gt;
=== Consider Data in transit and Data at rest ===&lt;br /&gt;
&lt;br /&gt;
Data protection in transit is the protection of this data while it’s traveling from network to network or being transferred from a local storage device to a cloud storage device – wherever data is moving, effective data protection measures for in transit data are critical as data is often considered less secure while in motion. &lt;br /&gt;
&lt;br /&gt;
While data at rest is sometimes considered to be less vulnerable than data in transit, attackers often find data at rest a more valuable target than data in motion. &lt;br /&gt;
&lt;br /&gt;
The risk profile for data in transit or data at rest depends on the security measures that are in place to secure data in either state. Protecting sensitive data both in transit and at rest is imperative for modern enterprises as attackers find increasingly innovative ways to compromise systems and steal data.&lt;br /&gt;
&lt;br /&gt;
== Create an information flow diagram ==&lt;br /&gt;
=== Whiteboard Your Architecture ===&lt;br /&gt;
&lt;br /&gt;
It is important to whiteboard system architecture by showing the major constraints and decisions in order to frame and start conversations. The value is actually twofold. If the architecture cannot be white-boarded, then it suggests that it is not well understood. If a clear and concise whiteboard diagram can be provided, others will understand it and it will be easier to communicate details. &lt;br /&gt;
&lt;br /&gt;
=== Manage to present your DFD in context of MVC ===&lt;br /&gt;
&lt;br /&gt;
In this step Data Flow Diagram should be divided the in the context of Model, View, Controller (MVC).&lt;br /&gt;
&lt;br /&gt;
=== Use tools to draw your diagram ===&lt;br /&gt;
&lt;br /&gt;
If you don’t like to manually draw your DFD; there are several tools available that could be used:&lt;br /&gt;
&lt;br /&gt;
==== Poirot ====&lt;br /&gt;
&lt;br /&gt;
The Poirot tool isolates and diagnoses defects through fault modelling and simulation. Along with a carefully selected partitioning strategy, functional and sequential test pattern applications show success with circuits having a high degree of observability.&lt;br /&gt;
&lt;br /&gt;
==== MS Threat modeling ====&lt;br /&gt;
&lt;br /&gt;
A tool that helps in finding threats in the design phase of software projects.&lt;br /&gt;
&lt;br /&gt;
== Define Data Flow over your DFD ==&lt;br /&gt;
&lt;br /&gt;
Define Data Flows over the organization Data Flow Diagram.&lt;br /&gt;
&lt;br /&gt;
== Define Trust Boundaries ==&lt;br /&gt;
&lt;br /&gt;
Define any distinct&amp;amp;nbsp;boundaries (External boundaries and Internal boundaries) within which a system&amp;amp;nbsp;trusts&amp;amp;nbsp;all sub-systems (including data).&lt;br /&gt;
&lt;br /&gt;
== Define applications user roles and trust levels ==&lt;br /&gt;
&lt;br /&gt;
Define access rights that the application will grant to external entities and internal entities.&lt;br /&gt;
&lt;br /&gt;
== Highlight Authorization per user role over the DFD ==&lt;br /&gt;
&lt;br /&gt;
Highlight Authorization per user role, for example, defining app users’ role, admins’ role, anonymous visitors’ role...etc.&lt;br /&gt;
&lt;br /&gt;
== Define Application Entry points ==&lt;br /&gt;
&lt;br /&gt;
Define the interfaces through which potential attackers can interact with the application or supply it with data.&lt;br /&gt;
&lt;br /&gt;
= Identify Threat Agents =&lt;br /&gt;
== Define all possible threats ==&lt;br /&gt;
&lt;br /&gt;
Identify Possible Attackers threat agents that could exist within the Target of Evaluation. Use Means, Motive, and Opportunities to understand Threats posed by Attackers. Then associate threat agents with system components they can directly interact with.&lt;br /&gt;
&lt;br /&gt;
Work on minimizing the number of threat agents by: &lt;br /&gt;
&lt;br /&gt;
* Treating them as equivalent classes. &lt;br /&gt;
&lt;br /&gt;
* Considering attacker’s motivation when evaluating likelihood.&lt;br /&gt;
* Consider insider Threats &lt;br /&gt;
&lt;br /&gt;
The user of this cheat can depend on the following list of risks and threat libraries sources to define the possible threats an application might be facing:&lt;br /&gt;
&lt;br /&gt;
# Risks with OWASP Top 10.&lt;br /&gt;
# Testing Procedure with OWASP ASVS.&lt;br /&gt;
# Risks with SANS Top 25.&lt;br /&gt;
# MS STRIDE.&lt;br /&gt;
&lt;br /&gt;
== Map Threat agents to application Entry points ==&lt;br /&gt;
&lt;br /&gt;
Map threat agents to application entry point, whether it is a login process, a registration process or whatever it might be and consider insider Threats.&lt;br /&gt;
&lt;br /&gt;
== Draw attack vectors and attacks tree ==&lt;br /&gt;
&lt;br /&gt;
During this phase conduct the following activities: &lt;br /&gt;
&lt;br /&gt;
* Draw attack vectors and attacks tree.&lt;br /&gt;
* Identify Use Cases/Abuse Cases. &lt;br /&gt;
* Re-Define attack vectors to consider multi-step attacks.&lt;br /&gt;
&lt;br /&gt;
== Mapping Abuse Cases to Use Cases ==&lt;br /&gt;
== Re-Define attack vectors ==&lt;br /&gt;
&lt;br /&gt;
In most cases after defining the attack vectors, the compromised user role could lead to further attacks into the application. For example, assuming that an internet banking user credentials could be compromised, the user of this cheat sheet has to then redefine the attack vectors that could result from compromising the user’s credentials and so on. &lt;br /&gt;
&lt;br /&gt;
= Write your Threat traceability matrix =&lt;br /&gt;
== Define the Impact and Probability for each threat ==&lt;br /&gt;
&lt;br /&gt;
Enumerate Attacks posed by most dangerous attacker in designated areas of the logical and physical maps of the target of evaluation.&lt;br /&gt;
&lt;br /&gt;
Assume the attacker has a zero day, because he does. In this methodology, we assume compromise; because a zero day will exist or already does exist (even if we don't know about it). This is about what can be done by skilled attackers, with much more time, money, motive and opportunity than we have.&lt;br /&gt;
&lt;br /&gt;
Use risk management methodology to determine the risk behind the threat&lt;br /&gt;
&lt;br /&gt;
Create risks in risk log for every identified threat or attack to any assets. A risk assessment methodology is followed in order to identify the risk level for each vulnerability and hence for each server. &lt;br /&gt;
&lt;br /&gt;
Here we will highlight two risk methodology that could be used:&lt;br /&gt;
&lt;br /&gt;
=== DREAD ===&lt;br /&gt;
&lt;br /&gt;
DREAD, is about evaluating each existing vulnerability using a mathematical formula to retrieve the vulnerability’s corresponding risk. The '''DREAD''' formula is divided into 5 main categories:&lt;br /&gt;
&lt;br /&gt;
* '''D'''amage - how bad would an attack be?&lt;br /&gt;
* '''R'''eproducibility - how easy it is to reproduce the attack?&lt;br /&gt;
* '''E'''xploitability - how much work is it to launch the attack?&lt;br /&gt;
* '''A'''ffected users - how many people will be impacted?&lt;br /&gt;
* '''D'''iscoverability - how easy it is to discover the threat?&lt;br /&gt;
&lt;br /&gt;
'''DREAD''' formula is: &lt;br /&gt;
&lt;br /&gt;
Risk Value = (Damage + Affected users) x (Reproducibility + Exploitability + Discoverability).&lt;br /&gt;
&lt;br /&gt;
Then the risk level is determined using defined thresholds below.&lt;br /&gt;
&lt;br /&gt;
=== PASTA ===&lt;br /&gt;
&lt;br /&gt;
PASTA, Attack Simulation &amp;amp; Threat Analysis (PASTA) is a complete methodology to perform application threat modleing. PASTA introduces a risk-centric methodology aimed at applying security countermeasures that are commensurate to the possible impact that could be sustained from defined threat models, vulnerabilities, weaknesses, and attack patterns. &lt;br /&gt;
&lt;br /&gt;
PASTA introduces a complete risk analysis and evaluation procedures that you can follow to evaluate the risk for each of the identified threat. The main difference in using PASTA Approach is that you should evaluate the impact early on in the analysis phase instead of addressing the impact at the step of evaluating the risk.&lt;br /&gt;
&lt;br /&gt;
The idea behind addressing the impact earlier in PASTA approach is that the audience that knows impact knows the consequences of product or use case failures more than participants in the threat analysis phase.&lt;br /&gt;
&lt;br /&gt;
Application security risk assessments are not enough because they&amp;amp;nbsp;are very binary and leverage a control framework basis for denoting risks. It is recommended to contextually look at threats, impacts, probability, effectiveness of countermeasures that may be present. R=(T*V*P*I)/Countermeasures&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more details about PASTA:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/a/aa/AppSecEU2012_PASTA.pdf &lt;br /&gt;
&lt;br /&gt;
== Rank Risks ==&lt;br /&gt;
&lt;br /&gt;
Using risk matrix rank risks from most severe to least severe based on Means, Motive &amp;amp; Opportunity. Below is sample risk matrix table, depending on your risk approach you can define deferent risk ranking matrix:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 1 to 12 [Risk Level: Notice]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 13 to 18 [Risk Level: Low]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 19 to 36 [Risk Level: Meduim]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 37 to 54 [Risk Level: High]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Determine Countermeasures and Mitigation. =&lt;br /&gt;
&lt;br /&gt;
Identify risk owners and agree on risk mitigation with risk owners and stakeholders. Provide the needed controls in forms of code upgrades and configuration updates to reduce risks to acceptable levels. &lt;br /&gt;
&lt;br /&gt;
== Identify Risk Owners ==&lt;br /&gt;
&lt;br /&gt;
For the assessors: After defining and analysing the risks, the assessor should be working on the mitigation plan by firstly identifying risk owners which is the personnel that is responsible for mitigating the risk. i.e. one of the information security team or the development team. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For the designers or the architects: they should assign the risk mitigation to the development team to consider it while building the application. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Agree on Risk Mitigation With Risk Owners and Stakeholders ==&lt;br /&gt;
== Build Your Risk Treatment Strategy ==&lt;br /&gt;
&lt;br /&gt;
* Reduce: building controls if the form of code upgrades, confirming a specific design for the application or building a specific configuration during the deployment phase to make sure that application risk is reduced. &lt;br /&gt;
* Transfer: For a specific component in the application the risk can be transferred to an outsourced third party to develop that component and making sure that the third party is doing the right testing for the component; or during the deployment phase, outsourcing a third party to do the deployment and transferring that risk to that third party. &lt;br /&gt;
* Avoid: an example of avoiding the risk is disabling a specific function in the application that is the source for that risk. &lt;br /&gt;
* Accept: if the risk is within acceptable criteria set earlier, in that case the designer risk owner can accept that risk. &lt;br /&gt;
&lt;br /&gt;
For the assessor this is considered that last step in the assessment process. The following steps should be conducted by the risk owner, however, the assessor shall engage in 6.5 (Testing risk treatment) to verify the remediation. &lt;br /&gt;
&lt;br /&gt;
== Select Appropriate Controls to Mitigate the Risk ==&lt;br /&gt;
&lt;br /&gt;
Selecting one of the controls to reduce the risk, either by upgrading the code, or building a specific configuration during the deployment phase and so on. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Risk Treatment to Verify Remediation ==&lt;br /&gt;
&lt;br /&gt;
Mitigation controls will not vanish the risk completely, rather, it would just reduce the risk. In this case, the user of this cheat sheet should measure the value of the risk after applying the mitigation controls. The value of the risk should be reduced to the acceptable criteria set earlier. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Reduce Risk in Risk Log for Verified Treated Risk ==&lt;br /&gt;
&lt;br /&gt;
After applying the mitigation and measuring the new risk value, the user of this cheat sheet should update the risk log to verify that risk has been reduced. &lt;br /&gt;
&lt;br /&gt;
== Periodically Retest Risk ==&lt;br /&gt;
&lt;br /&gt;
= Appendix =&lt;br /&gt;
'' Sample Design for Implementation View in 4+1 Model  ''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors and Primary Editors  ==&lt;br /&gt;
&lt;br /&gt;
Mohamed Alfateh &lt;br /&gt;
== Project Supporters  ==&lt;br /&gt;
Ahmed Kanoma&lt;br /&gt;
&lt;br /&gt;
== Other Cheatsheets ==&lt;br /&gt;
&lt;br /&gt;
{{Cheatsheet_Navigation_Body}}&lt;br /&gt;
[[Category:Cheatsheets]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245874</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245874"/>
				<updated>2018-12-09T11:49:11Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challenges (By: '''Ahmed Saafan''')&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challenges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challenges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245873</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245873"/>
				<updated>2018-12-09T11:47:30Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''1- Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challamges (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challamges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challamges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''2- CSCamp OWASP Cairo Chapter Sessions'' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I- Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
II-PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245872</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245872"/>
				<updated>2018-12-09T11:45:50Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp  ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''Women CTF Preparation Day'' &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challamges (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challamges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challamges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''CSCamp OWASP Cairo Chapter Sessions''' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245871</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245871"/>
				<updated>2018-12-09T11:44:51Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 13 Dec. 2018 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Women CTF Preparation Day''' &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time.&amp;lt;br /&amp;gt; &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
No need for the event ticket to attend the CTF preparation day(Planned 13 December 2018). For the CSCamp Event (on 14 &amp;amp;15 December 2018); the Attendance will require a conference ticket, please contact us if you coudn't able to get a ticket.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Greek Campus, Tahrir Sq., Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
December 13th, 2018&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 PM until 04:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 to 11:30 -  Web Security Challamges (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 to 12:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 to 13:30 -  Malware Reverse Engineering Challamges (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
13:30 to 14:00 - Break&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
14:00 to 15:30 -  Digital Forensics Challamges (By: '''Mohamed Talaat''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''CSCamp OWASP Cairo Chapter Sessions''' &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Focus Group: Security Management Problems(By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: Egyptian Cybercrime Law (Panel Moderator: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;(By: '''Dr. Mohamed Hegazy''', '''Dr. Marianne Amir''' and '''Adel Abdulmonim''')&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, December 15th, 2018&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=245373</id>
		<title>Threat Modeling Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Threat_Modeling_Cheat_Sheet&amp;diff=245373"/>
				<updated>2018-11-22T13:46:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: The draft version for the new updated sheet&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; __NOTOC__&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Cheatsheets-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
 __TOC__{{TOC hidden}}&lt;br /&gt;
''DRAFT CHEAT SHEET ''&lt;br /&gt;
= Introduction =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Objective of the Threat Modelling Control Cheat Sheet – To provide guidance to architects, designers and reviewers, on deriving threat models for applications.&lt;br /&gt;
&lt;br /&gt;
Audience: &lt;br /&gt;
&lt;br /&gt;
# Designers and Architects&lt;br /&gt;
# Assessors: Threat&amp;amp;nbsp;Modeling&amp;amp;nbsp;SMEs or Security&amp;amp;nbsp;Assessors&amp;amp;nbsp;who are responsible for analyzing the security of the entire applciations’ components.&lt;br /&gt;
&lt;br /&gt;
This cheat sheet provides guidance to assess existing apps as well as new apps. The instructions in here will help designer and architects address applications risks in an early stage of the development life cycle to help developers consider these risks while writing the code. It will also help assessors to look at risks from a comprehensive perspective. &lt;br /&gt;
&lt;br /&gt;
Following the guidance in this cheat sheet, the assessors will list all possible risks and then verifies whether there are enough security controls to protect against these risks. The assessor will then give better recommendations on how to mitigate these risks. It will help the assessor discover logical attacks. In general, the threat modelling will help designers, architects and assessors discover logical attacks. &lt;br /&gt;
&lt;br /&gt;
= Preparation =&lt;br /&gt;
== Understand Risk Management Basics in Context of Application Security ==&lt;br /&gt;
&lt;br /&gt;
Understand the Relation between Risk, Threats, and Vulnerabilities &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Understand Threat Modeling Terminologies ==&lt;br /&gt;
=== Asset, Threat Agent, Attack Surface, Likelihood, Impact, Control, Mitigation, Tractability Matrix ===&lt;br /&gt;
&lt;br /&gt;
Information Asset: is a body of knowledge that is organized and managed as a single entity. Like any other corporate&amp;amp;nbsp;asset, an organization's&amp;amp;nbsp;information assets have financial value.&lt;br /&gt;
&lt;br /&gt;
Threat Agent: The term&amp;amp;nbsp;Threat Agent&amp;amp;nbsp;is used to indicate an individual or group that can manifest athreat. It is fundamental to identify who would want to exploit the assets of a company, and how they might use them against the company.&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Attack Surface: The&amp;amp;nbsp;attack surface&amp;amp;nbsp;of a software environment is the sum of the different points (the &amp;quot;attack&amp;amp;nbsp;vectors&amp;quot;) where an unauthorized user (the &amp;quot;attacker&amp;quot;) can try to enter data to or extract data from an environment.&lt;br /&gt;
&lt;br /&gt;
Likelihood: Likelihood of threat event initiation or occurrence represents the degree to which a threat actor will carry out a threat. The likelihood of threat events resulting in adverse impacts estimates the possibility that a threat event would result in an actual outcome. The combined analysis of both threat assessment vectors impacts established an overall threat likelihood.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Impact: the damage potential, such as the number of components that are affected by a threat.&lt;br /&gt;
&lt;br /&gt;
Control: the safeguard or countermeasure to avoid, detect, counteract, or minimize security risks to information, computer systems, or other assets.&lt;br /&gt;
&lt;br /&gt;
Mitigation: A systematic reduction in the extent of exposure to a risk and/or the likelihood of its occurrence. &lt;br /&gt;
&lt;br /&gt;
Tractability Matrix: a grid that allows documentation and easy viewing of what is required for a system's security.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
== Define Objectives ==&lt;br /&gt;
&lt;br /&gt;
Before starting the threat modelling process; it is important to identify business objectives of the applications, and identify security &amp;amp; compliance requirements. This is very important to be defined in advance to help evaluating the impact of any vulnerability during the risk analysis process.&lt;br /&gt;
&lt;br /&gt;
= Identify application design =&lt;br /&gt;
&lt;br /&gt;
Understanding application design is a key activity to perform application threat modelling. It will enable the user of this cheat sheet to draw an accurate data flow diagram. Therefore, it will be easier to identify all possible risks. Moreover, the more the user of this cheat sheet understands application design, the better they will understand logical application attacks. The objective of the design document is to enumerate application components. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Review the application design document ==&lt;br /&gt;
&lt;br /&gt;
If you are not performing threat modelling during the development (in the design phase) so you have to review the application design documents to understand the application structure and to help generating the data flow diagram. If there are no available design documents so you have to create one. Move to next section &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Create design documents ==&lt;br /&gt;
&lt;br /&gt;
There are many ways to generate design documents; the 4+1 view model is one of the matured approaches to build your design document. Reference to 4+1 view model of architecture: [http://ieeexplore.ieee.org/abstract/document/469759/?reload=true http://ieeexplore.ieee.org/abstract/document/469759/?reload=true] &lt;br /&gt;
&lt;br /&gt;
Please note that, the 4+1 is comprehensive, you may use any other design model during this phase.&lt;br /&gt;
&lt;br /&gt;
The following subsections show the details about 4+1 approach and how this could help in the threat modelling process:&lt;br /&gt;
&lt;br /&gt;
=== Logical View ===&lt;br /&gt;
&lt;br /&gt;
Create a logical map of the Target of Evaluation. &lt;br /&gt;
&lt;br /&gt;
'''Audience''': Designers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Functional Requirements: describes the design's object model. &lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Design model&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Implementation View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Programmers.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Software components: describes the layers and subsystems of the application.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Implementation model, components&lt;br /&gt;
&lt;br /&gt;
Please refer to the image in the appendix section for sample design for the implementation view. &lt;br /&gt;
&lt;br /&gt;
=== Process View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''Integrators.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''Non-functional requirements: describes the design's concurrency and synchronization aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''(no specific artifact).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Deployment View ===&lt;br /&gt;
&lt;br /&gt;
Create a physical map of the Target of Evaluation&lt;br /&gt;
&lt;br /&gt;
'''Audience''': Deployment managers.&lt;br /&gt;
&lt;br /&gt;
'''Area''': Topology: describes the mapping of the software onto the hardware and shows the system's distributed aspects.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts''': Deployment model.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Use-Case View ===&lt;br /&gt;
&lt;br /&gt;
'''Audience: '''all the stakeholders of the system, including the end-users.&lt;br /&gt;
&lt;br /&gt;
'''Area: '''describes the set of scenarios and/or use cases that represent some significant, central functionality of the system.&lt;br /&gt;
&lt;br /&gt;
'''Related Artifacts: '''Use-Case Model, Use-Case documents&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Decompose and Model the System =&lt;br /&gt;
&lt;br /&gt;
Gain an understanding of how the system works to perform a threat model, it is important to understand how the system works and interacts with its ecosystem. To start with creating a high-level information flow diagram, like the following:&lt;br /&gt;
&lt;br /&gt;
# Identify the trusted boundaries of your system / application / module / ecosystem that you may want to start off with.&lt;br /&gt;
# Add actors – internal and external&lt;br /&gt;
# Define internal trusted boundaries. These can be the different security zones that have been designed&lt;br /&gt;
# Relook at the actors you have identified in #2 for consistency&lt;br /&gt;
# Add information flows&lt;br /&gt;
# Identify the information elements and their classification as per your information classification policy&lt;br /&gt;
# Where possible add assets to the identified information flows.&lt;br /&gt;
&lt;br /&gt;
== Define and Evaluate your Assets ==&lt;br /&gt;
&lt;br /&gt;
Assets involved in the information flow should be defined and evaluated according to their value of confidentiality, integrity and availability. &lt;br /&gt;
&lt;br /&gt;
=== Consider Data in transit and Data at rest ===&lt;br /&gt;
&lt;br /&gt;
Data protection in transit is the protection of this data while it’s traveling from network to network or being transferred from a local storage device to a cloud storage device – wherever data is moving, effective data protection measures for in transit data are critical as data is often considered less secure while in motion. &lt;br /&gt;
&lt;br /&gt;
While data at rest is sometimes considered to be less vulnerable than data in transit, attackers often find data at rest a more valuable target than data in motion. &lt;br /&gt;
&lt;br /&gt;
The risk profile for data in transit or data at rest depends on the security measures that are in place to secure data in either state. Protecting sensitive data both in transit and at rest is imperative for modern enterprises as attackers find increasingly innovative ways to compromise systems and steal data.&lt;br /&gt;
&lt;br /&gt;
== Create an information flow diagram ==&lt;br /&gt;
=== Whiteboard Your Architecture ===&lt;br /&gt;
&lt;br /&gt;
It is important to whiteboard system architecture by showing the major constraints and decisions in order to frame and start conversations. The value is actually twofold. If the architecture cannot be white-boarded, then it suggests that it is not well understood. If a clear and concise whiteboard diagram can be provided, others will understand it and it will be easier to communicate details. &lt;br /&gt;
&lt;br /&gt;
=== Manage to present your DFD in context of MVC ===&lt;br /&gt;
&lt;br /&gt;
In this step Data Flow Diagram should be divided the in the context of Model, View, Controller (MVC).&lt;br /&gt;
&lt;br /&gt;
=== Use tools to draw your diagram ===&lt;br /&gt;
&lt;br /&gt;
If you don’t like to manually draw your DFD; there are several tools available that could be used:&lt;br /&gt;
&lt;br /&gt;
==== Poirot ====&lt;br /&gt;
&lt;br /&gt;
The Poirot tool isolates and diagnoses defects through fault modelling and simulation. Along with a carefully selected partitioning strategy, functional and sequential test pattern applications show success with circuits having a high degree of observability.&lt;br /&gt;
&lt;br /&gt;
==== MS Threat modeling ====&lt;br /&gt;
&lt;br /&gt;
A tool that helps in finding threats in the design phase of software projects.&lt;br /&gt;
&lt;br /&gt;
== Define Data Flow over your DFD ==&lt;br /&gt;
&lt;br /&gt;
Define Data Flows over the organization Data Flow Diagram.&lt;br /&gt;
&lt;br /&gt;
== Define Trust Boundaries ==&lt;br /&gt;
&lt;br /&gt;
Define any distinct&amp;amp;nbsp;boundaries (External boundaries and Internal boundaries) within which a system&amp;amp;nbsp;trusts&amp;amp;nbsp;all sub-systems (including data).&lt;br /&gt;
&lt;br /&gt;
== Define applications user roles and trust levels ==&lt;br /&gt;
&lt;br /&gt;
Define access rights that the application will grant to external entities and internal entities.&lt;br /&gt;
&lt;br /&gt;
== Highlight Authorization per user role over the DFD ==&lt;br /&gt;
&lt;br /&gt;
Highlight Authorization per user role, for example, defining app users’ role, admins’ role, anonymous visitors’ role...etc.&lt;br /&gt;
&lt;br /&gt;
== Define Application Entry points ==&lt;br /&gt;
&lt;br /&gt;
Define the interfaces through which potential attackers can interact with the application or supply it with data.&lt;br /&gt;
&lt;br /&gt;
= Identify Threat Agents =&lt;br /&gt;
== Define all possible threats ==&lt;br /&gt;
&lt;br /&gt;
Identify Possible Attackers threat agents that could exist within the Target of Evaluation. Use Means, Motive, and Opportunities to understand Threats posed by Attackers. Then associate threat agents with system components they can directly interact with.&lt;br /&gt;
&lt;br /&gt;
Work on minimizing the number of threat agents by: &lt;br /&gt;
&lt;br /&gt;
* Treating them as equivalent classes. &lt;br /&gt;
&lt;br /&gt;
* Considering attacker’s motivation when evaluating likelihood.&lt;br /&gt;
* Consider insider Threats &lt;br /&gt;
&lt;br /&gt;
The user of this cheat can depend on the following list of risks and threat libraries sources to define the possible threats an application might be facing:&lt;br /&gt;
&lt;br /&gt;
# Risks with OWASP Top 10.&lt;br /&gt;
# Testing Procedure with OWASP ASVS.&lt;br /&gt;
# Risks with SANS Top 25.&lt;br /&gt;
# MS STRIDE.&lt;br /&gt;
&lt;br /&gt;
== Map Threat agents to application Entry points ==&lt;br /&gt;
&lt;br /&gt;
Map threat agents to application entry point, whether it is a login process, a registration process or whatever it might be and consider insider Threats.&lt;br /&gt;
&lt;br /&gt;
== Draw attack vectors and attacks tree ==&lt;br /&gt;
&lt;br /&gt;
During this phase conduct the following activities: &lt;br /&gt;
&lt;br /&gt;
* Draw attack vectors and attacks tree.&lt;br /&gt;
* Identify Use Cases/Abuse Cases. &lt;br /&gt;
* Re-Define attack vectors to consider multi-step attacks.&lt;br /&gt;
&lt;br /&gt;
== Mapping Abuse Cases to Use Cases ==&lt;br /&gt;
== Re-Define attack vectors ==&lt;br /&gt;
&lt;br /&gt;
In most cases after defining the attack vectors, the compromised user role could lead to further attacks into the application. For example, assuming that an internet banking user credentials could be compromised, the user of this cheat sheet has to then redefine the attack vectors that could result from compromising the user’s credentials and so on. &lt;br /&gt;
&lt;br /&gt;
= Write your Threat traceability matrix =&lt;br /&gt;
== Define the Impact and Probability for each threat ==&lt;br /&gt;
&lt;br /&gt;
Enumerate Attacks posed by most dangerous attacker in designated areas of the logical and physical maps of the target of evaluation.&lt;br /&gt;
&lt;br /&gt;
Assume the attacker has a zero day, because he does. In this methodology, we assume compromise; because a zero day will exist or already does exist (even if we don't know about it). This is about what can be done by skilled attackers, with much more time, money, motive and opportunity than we have.&lt;br /&gt;
&lt;br /&gt;
Use risk management methodology to determine the risk behind the threat&lt;br /&gt;
&lt;br /&gt;
Create risks in risk log for every identified threat or attack to any assets. A risk assessment methodology is followed in order to identify the risk level for each vulnerability and hence for each server. &lt;br /&gt;
&lt;br /&gt;
Here we will highlight two risk methodology that could be used:&lt;br /&gt;
&lt;br /&gt;
=== DREAD ===&lt;br /&gt;
&lt;br /&gt;
DREAD, is about evaluating each existing vulnerability using a mathematical formula to retrieve the vulnerability’s corresponding risk. The '''DREAD''' formula is divided into 5 main categories:&lt;br /&gt;
&lt;br /&gt;
* '''D'''amage - how bad would an attack be?&lt;br /&gt;
* '''R'''eproducibility - how easy it is to reproduce the attack?&lt;br /&gt;
* '''E'''xploitability - how much work is it to launch the attack?&lt;br /&gt;
* '''A'''ffected users - how many people will be impacted?&lt;br /&gt;
* '''D'''iscoverability - how easy it is to discover the threat?&lt;br /&gt;
&lt;br /&gt;
'''DREAD''' formula is: &lt;br /&gt;
&lt;br /&gt;
Risk Value = (Damage + Affected users) x (Reproducibility + Exploitability + Discoverability).&lt;br /&gt;
&lt;br /&gt;
Then the risk level is determined using defined thresholds below.&lt;br /&gt;
&lt;br /&gt;
=== PASTA ===&lt;br /&gt;
&lt;br /&gt;
PASTA, Attack Simulation &amp;amp; Threat Analysis (PASTA) is a complete methodology to perform application threat modleing. PASTA introduces a risk-centric methodology aimed at applying security countermeasures that are commensurate to the possible impact that could be sustained from defined threat models, vulnerabilities, weaknesses, and attack patterns. &lt;br /&gt;
&lt;br /&gt;
PASTA introduces a complete risk analysis and evaluation procedures that you can follow to evaluate the risk for each of the identified threat. The main difference in using PASTA Approach is that you should evaluate the impact early on in the analysis phase instead of addressing the impact at the step of evaluating the risk.&lt;br /&gt;
&lt;br /&gt;
The idea behind addressing the impact earlier in PASTA approach is that the audience that knows impact knows the consequences of product or use case failures more than participants in the threat analysis phase.&lt;br /&gt;
&lt;br /&gt;
Application security risk assessments are not enough because they&amp;amp;nbsp;are very binary and leverage a control framework basis for denoting risks. It is recommended to contextually look at threats, impacts, probability, effectiveness of countermeasures that may be present. R=(T*V*P*I)/Countermeasures&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For more details about PASTA:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/a/aa/AppSecEU2012_PASTA.pdf &lt;br /&gt;
&lt;br /&gt;
== Rank Risks ==&lt;br /&gt;
&lt;br /&gt;
Using risk matrix rank risks from most severe to least severe based on Means, Motive &amp;amp; Opportunity. Below is sample risk matrix table, depending on your risk approach you can define deferent risk ranking matrix:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 1 to 12 [Risk Level: Notice]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 13 to 18 [Risk Level: Low]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 19 to 36 [Risk Level: Meduim]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;Risk Value: 37 to 54 [Risk Level: High]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Determine countermeasures and mitigation. =&lt;br /&gt;
&lt;br /&gt;
Identify risk owners and agree on risk mitigation with risk owners and stakeholders. Provide the needed controls in forms of code upgrades and configuration updates to reduce risks to acceptable levels. &lt;br /&gt;
&lt;br /&gt;
== Identify risk owners ==&lt;br /&gt;
&lt;br /&gt;
For the assessors: After defining and analysing the risks, the assessor should be working on the mitigation plan by firstly identifying risk owners which is the personnel that is responsible for mitigating the risk. i.e. one of the information security team or the development team. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For the designers or the architects: they should assign the risk mitigation to the development team to consider it while building the application. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Agree on risk mitigation with risk owners and stakeholders ==&lt;br /&gt;
== Build your risk treatment strategy ==&lt;br /&gt;
&lt;br /&gt;
* Reduce: building controls if the form of code upgrades, confirming a specific design for the application or building a specific configuration during the deployment phase to make sure that application risk is reduced. &lt;br /&gt;
* Transfer: For a specific component in the application the risk can be transferred to an outsourced third party to develop that component and making sure that the third party is doing the right testing for the component; or during the deployment phase, outsourcing a third party to do the deployment and transferring that risk to that third party. &lt;br /&gt;
* Avoid: an example of avoiding the risk is disabling a specific function in the application that is the source for that risk. &lt;br /&gt;
* Accept: if the risk is within acceptable criteria set earlier, in that case the designer risk owner can accept that risk. &lt;br /&gt;
&lt;br /&gt;
For the assessor this is considered that last step in the assessment process. The following steps should be conducted by the risk owner, however, the assessor shall engage in 6.5 (Testing risk treatment) to verify the remediation. &lt;br /&gt;
&lt;br /&gt;
== Select appropriate controls to mitigate the risk ==&lt;br /&gt;
&lt;br /&gt;
Selecting one of the controls to reduce the risk, either by upgrading the code, or building a specific configuration during the deployment phase and so on. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test risk treatment to verify remediation ==&lt;br /&gt;
&lt;br /&gt;
Mitigation controls will not vanish the risk completely, rather, it would just reduce the risk. In this case, the user of this cheat sheet should measure the value of the risk after applying the mitigation controls. The value of the risk should be reduced to the acceptable criteria set earlier. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Reduce risk in risk log for verified treated risk ==&lt;br /&gt;
&lt;br /&gt;
After applying the mitigation and measuring the new risk value, the user of this cheat sheet should update the risk log to verify that risk has been reduced. &lt;br /&gt;
&lt;br /&gt;
== Periodically retest risk ==&lt;br /&gt;
&lt;br /&gt;
= Appendix =&lt;br /&gt;
'' Sample Design for Implementation View in 4+1 Model  ''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Authors and Primary Editors  ==&lt;br /&gt;
&lt;br /&gt;
Mohamed Alfateh &lt;br /&gt;
Ahmed Kanoma&lt;br /&gt;
&lt;br /&gt;
== Other Cheatsheets ==&lt;br /&gt;
&lt;br /&gt;
{{Cheatsheet_Navigation_Body}}&lt;br /&gt;
[[Category:Cheatsheets]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245350</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=245350"/>
				<updated>2018-11-21T17:57:38Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: Adding Ahmed Saafan to the chapter board members&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly], Ahmed Saafan and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=243501</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=243501"/>
				<updated>2018-09-18T04:47:32Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Note: The OWASP session is free to attend, no need to have event ticket.&amp;lt;br /&amp;gt;&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=243500</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=243500"/>
				<updated>2018-09-18T04:45:14Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: Adding Chapter participation in Arab Security Conf.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the Arab Security Conference 2018 ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Arab Security Conference is an annual cyber security conference held in Cairo, Egypt. It strives to raise Cyber Security Awareness in the Arab world.&amp;lt;br /&amp;gt;&lt;br /&gt;
Event link: https://www.arabsecurityconference.com&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Nile Ritz-Carlton, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
23 - 24 September 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: 03:00 PM - 04:00 PM -  Wargames Hall &amp;lt;br /&amp;gt;&lt;br /&gt;
Web Application Security Testing using ZAP. (30 min) [By: '''Hassan Mohamed''' and '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=242177</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=242177"/>
				<updated>2018-07-30T19:01:12Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
5 - 6 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=242042</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=242042"/>
				<updated>2018-07-22T21:09:36Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: Updating the chapter news with the ITI Juniors Academy event&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Juniors Academy Program ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Juniors Academy Program link: http://www.iti.gov.eg/Site/Offers/JuniorsAcademy&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
8 - 9 August 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP days:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Day 1: Application development basics, introduction to web technologies and OWASP community and projects briefing. &amp;lt;br /&amp;gt;&lt;br /&gt;
Day 2: Introduction application security and hands on practices on number of OWASP top 10 vulnerabilities.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=240033</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=240033"/>
				<updated>2018-04-18T16:09:34Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh''' and '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=240032</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=240032"/>
				<updated>2018-04-18T16:08:54Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: Updating the chapter activities with the new ITI event participation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://www.mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://www.mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
19 - 21 April 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to Block-chain security (30 min) [By: '''Mohamed Alfateh'' and ''Fady Othman'' ']&amp;lt;br /&amp;gt;&lt;br /&gt;
What is new with OWASP Top 10 (30 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=238351</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=238351"/>
				<updated>2018-03-05T18:34:20Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=238349</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=238349"/>
				<updated>2018-03-05T18:32:33Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the third year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: https://goo.gl/wrTw9R&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
6 March 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 new release  (45 min) [By: '''Mohamed Alfateh''' and '''Hassan Morad''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236331</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236331"/>
				<updated>2017-12-19T20:29:42Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''' and '''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236330</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236330"/>
				<updated>2017-12-19T20:28:47Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction for OWASP Projects (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Access Control Attacks (45 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
5- Broken Access Control Attacks Mitigation (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
6- Broken Access Control Attacks and Mitigation Demos (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Sessions speakers: '''&amp;lt;br /&amp;gt;[''Hassan Mohammed''',''Ahmed Elhady''' ]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236208</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236208"/>
				<updated>2017-12-12T15:12:22Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236207</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236207"/>
				<updated>2017-12-12T15:11:20Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 15 Dec. 2017 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, December 15th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
04:30 PM until 06:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Diffusing A Bomb With Reverse Engineering&amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A while ago I stumbled upon an online reverse engineering challenge, I downloaded the challenge and from the beginning it caught my attention. I started reversing and I realized that it was a well designed challenge that is perfect to teach reverse engineering. after solving the challenge I was disappointed when I looked online to see how other people solved it because it was solved in a way that teaches them too little.&lt;br /&gt;
In this workshop I will “diffuse” the “bomb” using multiple methods and multiple tools (hopefully IDA, GDB, EDB, Radare2) to make the most of it and trying to teach something new on the way.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Defending Applications by putting them under the Proactive SOC spotlight &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most companies are trying to shift their Security Operations Center (SOC) from a reactive to a proactive posture. Putting the application layer under a proactive monitoring and analysis is a critical activity to anticipates and pre-empts incidents to prevent their occurrence. In this talk we will discuss different techniques to proactively anticipate web threats and act upon anticipation proactively rather than passively. During the session, we will show how you could use OWASP AppSensor to feed data into SOC and to respond to analysis results. The session will introduce number of corresponding SIEM use cases that could be implemented in deferent SIEM technologies.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PANEL DISCUSSION: WHAT’S NEW WITH OWASP TOP 10 &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan, Hassan Morad, Mohamed Alfateh and Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP released a major update to the OWASP top 10 project. In this session we will look at what is new in the 2017 version. We will discuss the major changes to the top 10 list and whether or not such changes brings better value to application security.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236206</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=236206"/>
				<updated>2017-12-12T15:04:39Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
22 December 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
TBD &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=234643</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=234643"/>
				<updated>2017-10-26T07:57:48Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- BeEF - Browser Exploiatation Framework Demo (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
6- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
25 November 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 December 2017  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Jan 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cairo&amp;diff=234642</id>
		<title>Cairo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cairo&amp;diff=234642"/>
				<updated>2017-10-26T07:09:52Z</updated>
		
		<summary type="html">&lt;p&gt;Mohamed Alfateh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Cairo|extra=The chapter leader is [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]. Chapter Board Members are:[mailto:adel.abdel.moneim@owasp.org Adel Abdel Moneim], [mailto:hassan.mourad@owasp.org Hassan Mourad], [mailto:ahmed.mashaly@owasp.org Ahmed Mashaly] and [mailto:fady.othman@owasp.org Fady Othman]. |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-egypt|emailarchives=http://lists.owasp.org/pipermail/owasp-egypt}}&lt;br /&gt;
&lt;br /&gt;
====== Local News ====== &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== Upcomming Events  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 3: Cross Site Scripting '''&amp;lt;br /&amp;gt;&lt;br /&gt;
XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
28 October 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: (First Session starts 10 AM)'''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- What is the new in CR2 of OWASP top 10 2017 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Cross Site Scripting Attacks (45 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Cross Site Scripting Attacks Demos (30 min) [By: '''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Cross Site Scripting Attacks Mitigation (30 min) [By: '''Hassan Mohammed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
5- Cross Site Scripting Attacks Mitigation Demos (30 min) [By: ''Abdulrahman Nour''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 4: Broken Access Control '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
25 November 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 5: Security Misconfiguration '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Good security requires having a secure configuration defined and deployed for the application, frameworks, application server, web server, database server, platform, etc. Secure settings should be defined, implemented, and maintained, as defaults are often insecure. Additionally, software should be kept up to date.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
16 December 2017  &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 6: Sensitive Data Exposure '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Jan 2018 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the ITI's Mobile Developer Weekend Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''OWASP Cairo chapter is participating this year in the ITI's Mobile Developer Weekend Event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://mobiledeveloperweekend.net/event/agenda.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://mobiledeveloperweekend.net/attendee/registration.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 April 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top 10 Risks and Mitigation (60 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''For the second year, OWASP Cairo chapter is participating in the CIT information Security event'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Event Agenda http://login.qsend.it/t/r-l-yuflya-dktihhjddj-r/.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Event Registration link: http://login.qsend.it/t/r-l-yuflya-dktihhjddj-o/&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
27 March 2017 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Session: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Web and Mobile applications Advanced User Tracking (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Day 2: Broken Authentication and Session Management '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Application functions related to authentication and session management are often not implemented correctly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities. The &amp;quot;Broken Authentication and Session Management&amp;quot; day includes three sessions covering the relevent web attacks and attacks mitigation.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI Information Technology Institute - Smart Village - Building, B148, - km 28, Cairo-Alexandria Desert Road, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
24 December 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to OWASP top 10 (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Broken Authentication and Session Management Attacks (45 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
3- Broken Authentication and Session Management Attacks Demos (30 min) [By: '''Ahmed Alaa''']&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Broken Authentication and Session Management Attacks Mitigation (45 min) [By: '''Mohamed Alfateh''']&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 18 Nov. 2016 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the first OWASP session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, November 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
05:00 PM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Hidden Venom : Dangerous Formats &amp;lt;br /&amp;gt; (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In the past years, we have seen the development of client-side attacks and how hackers became smarter and smarter. We came to a realization that you don't really need a zero day or advanced exploit to spread a malware or ransomware. all what you need is a good social engineering trick and the knowledge of how to abuse a legitimate file format. In this talk, we will have a look at seemingly non-harmful file formats and how they can be abused to spread malware.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploiting PHP Serialized Objects for Authentication bypass &amp;lt;br /&amp;gt; (By: '''Ebrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
In this session, I will talk about PHP Serialized Objects as following:&lt;br /&gt;
1- What is PHP Serialized/Unserialize Objects and how it works, 2- Demo Code on PHP Serialized Objects, 3- Exploitation scenarios for Serialized Objects, 4- Practical example of exploiting Serialized Objects for Authentication bypass &amp;amp; Privilege Escalation.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Hidden Venom : Detecting APTs at web application layer &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detecting   and   defending   against   Multi - Stage  Advanced  Persistent  Threats  (APT)  Attacks  is a  challenge  for  mechanisms  that   are   static  in   its   nature   and   are based   on  blacklisting  and  malware  signature techniques. The comprehensive analysis and correlation can discover behavior indicative of APT-related attacks and data exfiltration. In the web application layer, other techniques are used to detect the sophisticated web attacks. In this presentation, we will discuss some techniques that could be used to deal with the APTs in the web application layer.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in FIRST Regional Symposium for Arab and African Regions, November 2nd 2016 =====  &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Cairo chapter will be a main contributor to FIRST regional symposium for Arab and African Regions that will be held in Egypt on the 2nd and 3rd of November in the city of Sharm ElSheikh.&amp;lt;br /&amp;gt;&lt;br /&gt;
https://www.first.org/events/symposium/egypt2016 &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Top 10 Awareness Program  ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
For those of you who missed our OWASP top 10 injection day, you get a second chance to attend it.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
We will be running the sessions again as a webinar next Thursday (1/9/2016) at 6 pm Cairo time.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The registration link for the webinar is &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
https://attendee.gotowebinar.com/register/4323912316534772740&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you then. Have a great day &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day 1: Injection Day '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Injection is an entire class of attacks that rely on injecting data into a web application in order to facilitate the execution or interpretation of malicious data in an unexpected manner. Examples of attacks within this class include Cross-Site Scripting (XSS), SQL Injection, Header Injection, Log Injection and Full Path Disclosure. I’m scratching the surface here.&lt;br /&gt;
&lt;br /&gt;
This class of attacks is every programmer’s bogeyman. They are the most common and successful attacks on the internet due to their numerous types, large attack surface, and the complexity sometimes needed to protect against them. The injection day includes three sessions covering the Injection Attacks and Mitigations, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Abbas Al-Akkad St., Madinet Nasr, Cairo, Egypt&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
20 August 2016 &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Day Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to Injection Attacks (45 min) [By: '''Hassan Mohamed''']&amp;lt;br /&amp;gt;&lt;br /&gt;
2- Advanced Techniques for Injection Attacks (45 min) [By: '''Fady Othman''']&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Injection Attacks Mitigations (45 min) [By: '''Ahmed Saafan''']&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in the CIT's Second Anual Cyber Security Event ===== &lt;br /&gt;
[[File:CIT-OWASP.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Event Presentations:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/c/cf/TH_CIT_OWASP_Cairo.pptx Hunting for the bad guys]&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/5/5f/SSA_CIT_OWASP_Cairo.pptx Software Security Assurance]&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The registration is not mandatory, please visit the event website for more details: http://cit-fei.org/en/Page/sc/security-conference&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 100 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Fairmont Hotel, Heliopolis, El Orouba Street, 11736, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Monday, May 30, 2016 at 7:00 PM&amp;lt;br /&amp;gt;&lt;br /&gt;
Tuesday, May 31, 2016 at 10:00 PM &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BIO:&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nadim Barsoum is a senior software security consultant who has worked for 13 years in the software industry, focused on the IT compliance needs of governmental institutions, private sector enterprises and banks. Nadim has helped organisations around the globe to plan, resource and initiate their Software Security Assurance programs, enabling them to realize the full potential of a structured, measurable approach to risk management and mitigation. By drawing upon a vast set of experiences in a variety of industries and environments, he has custom-tailored programs to meet the specific needs of clients, ensuring they realise the optimum return on their investments. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hunting for the bad guys &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promissing to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examin a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in IEEE MSB Event 29-30 Aprl 2016 ===== &lt;br /&gt;
[[File:OWASP_ieee_Monofia_3.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Moustafa Elnaggar Streat - Shebin Elkom، Monofia, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, April 29th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 30th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
09:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''OWASP Sessions: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Game Development (90 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- Exploit Writing Fundamental (90 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Application security Training for ITI Cyber security students ===== &lt;br /&gt;
[[File:Iti-egypt-logo-sm.jpg|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
ITI building - Smart Village، Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Wednesday, March 16th, 2016 and&amp;lt;br /&amp;gt;&lt;br /&gt;
Friday, March 18th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
09:00 AM until 07:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Application security event in Ain Shams University [Event Postponed]===== &lt;br /&gt;
[[File:ASU_logo.gif|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Will be opened soon, &amp;lt;br /&amp;gt;&lt;br /&gt;
It is free and we don't have limitation for the number of attendees &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Ain Shams University Khalifa El-Maamon St، Cairo,‬ 11566 , EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, April 9th, 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 02:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
1- Introduction to application security and OWASP academic program (30 min) &amp;lt;br /&amp;gt;&lt;br /&gt;
2- OWASP top 10 in details (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
3- OWASP AppSec Projects, how could students contributes and how to get support from Egyptian OWASP members (45 min)&amp;lt;br /&amp;gt;&lt;br /&gt;
4- Open Discussion panel &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Detailed agenda will be updated soon&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 20 Sep. 2015 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Intercontinental City Stars, Al saraya Hall, Nasr City, Cairo, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, September 20th, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 AM until 05:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Software Security Assurance &amp;lt;br /&amp;gt; (By: '''Nadim Barsoum''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Implementing a software security assurance program can be a daunting task that can leave program managers and consultants equally overwhelmed. In this talk we discuss the main building blocks of a software security assurance program and suggest light-weight methods for jump-starting your program with a focus on assurance activities and their relating governance aspects.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Mobile Application Security &amp;lt;br /&amp;gt; (By: '''Hassan Elhadary''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nowadays web applications are being transformed into mobile applications allowing users to perform security critical functions such as money transfers and bill payments from their mobile devices. Newly added features on mobile applications expose new attack surface for hackers and thus increase the challenges for developers to defend their mobile applications. This talk will focus on latest techniques utilized by attackers to conduct security attacks on mobile applications. It will include real life stories and demos inspired from professional experience and research in bug bounty programs. Finally, recommendations will be outlined to help developers mitigate most common attacks affecting mobile applications.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application Threat Modeling&amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to the US Computer Emergency Readiness Team (US-CERT), most successful cyber-attacks result from targeting and exploiting software vulnerabilities. Threat Modeling is a critical activity for identifying such vulnerabilities early in the development stages. In this talk, we will discuss application threat modeling process, how to perform threat modeling in systematic way and how to integrate threat modeling in your software development life-cycle. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter Event (May 2015) ===== &lt;br /&gt;
[[File:Logo_OWASP_Nile.png|thumb|400px]]&lt;br /&gt;
[[File:LogoBKlogo.png|thumb|300px]]&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-event-may-2015-tickets-16769346567?aff=affiliate1 Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:30 Standards of Information Security, Privacy and Governance in Enterprise Application Security&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:30 ZAP Project, New Release, New Features &amp;lt;br /&amp;gt; (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Break&lt;br /&gt;
01:00 – 02:00 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 03:00 WAF Evasion Techniques and Thoughts of Secure Coding &amp;lt;br /&amp;gt; (By: '''Ahmed Alaa''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University Juhayna Square - Sheikh Zayed, Giza,&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, May 9, 2015&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 3:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== OWASP Cairo Chapter in Bluekaizen CSCamp 2014 ===== &lt;br /&gt;
[[File:OWASP_Egypt-Bluekaizen.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
''' Registration Details:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
The Attendance will be free of charge without need for conference ticket, &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These sessions are served in the way of First Come First Served. The room has a limitation of 50 persons only. If you are interested to attend please try to be there before the session start by a good amount of time. &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
Nile University, New Campus, Sheikh Zayed District, 6th of October, Giza, EGYPT&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, November 29th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
02:30 AM until 05:30 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Event Agenda: '''&amp;lt;br /&amp;gt;&lt;br /&gt;
Advanced XSS Filter Evasion and Post Exploitation &amp;lt;br /&amp;gt; (By: '''Ahmed Saafan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Hands-on Reverse Engineering Android Malware &amp;lt;br /&amp;gt; (By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
Introduction to web crawling (build a smart web crawler)&amp;lt;br /&amp;gt; (By: '''Ayman Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Chapter Meeting (14 June 2014) ===== &lt;br /&gt;
[[File:EBI-Partner.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
Registration Portal:&lt;br /&gt;
[http://www.eventbrite.com/e/owasp-egypt-event-june-2014-tickets-11672018321?aff=owasppage Click Here]&lt;br /&gt;
&lt;br /&gt;
Meeting Agenda: &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10:30 Registration&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:15 US AppSec Conference 2013 – Brief about some Interesting Topics&amp;lt;br /&amp;gt; (By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:15 – 12:00 Sleeping your way out of the sandbox &amp;lt;br /&amp;gt; (By: '''Hassan Mourad''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Pwning the skiddies using the anonymity weapon&amp;lt;br /&amp;gt; (By: '''Ahmed Sultan''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:15 HTML5 security&amp;lt;br /&amp;gt; (By: '''Hassan Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:15 – 02:00 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
02:00 – 02:45 Anti &amp;quot;Anti-Crawling&amp;quot; Techniques&amp;lt;br /&amp;gt; (By: '''Ayman Mohammed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 03:30 Cloud Security Risks - Pain &amp;amp; Relief&amp;lt;br /&amp;gt; (By: '''Moataz Abd El Khalek''')&amp;lt;br /&amp;gt;&lt;br /&gt;
03:30 – 04:15 Mobile Application hacking and forensics&amp;lt;br /&amp;gt; (By: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&amp;lt;br /&amp;gt;&lt;br /&gt;
56 Gamaet El Dewal El Arabeya St - Al-Mohandiseen Building - In front of Moustafa mahmoud's mosque&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Date:''' &amp;lt;br /&amp;gt;&lt;br /&gt;
Saturday, June 14th, 2014&amp;lt;br /&amp;gt;&lt;br /&gt;
10:00 AM until 4:00 PM&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Chapter Facebook Page: https://www.facebook.com/OWASPCairo &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
Sessions Description &lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
'''Pwning the skiddies using the anonymity weapon'''&amp;lt;br /&amp;gt; &lt;br /&gt;
Proxy services and vpn servers are used widely all over the world&lt;br /&gt;
But , can you really depend on them as secure way to surf the WWW?&lt;br /&gt;
We gonna demonstrate how the such services are invisibly used to take over thousands of PCs every single hour.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Sleeping your way out of the sandbox''' &amp;lt;br /&amp;gt; &lt;br /&gt;
Recently, a new breed of security solutions appeared in the market, Sandbox based Antimalware solutions, promising to be the answer to advanced malware and APTs.&lt;br /&gt;
&lt;br /&gt;
Yet, as always, there are ways to circumvent any control. In this presentation we will examine a new technique to bypass sandbox based solutions, allowing malware to avoid detection and giving it a free pass to your network.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''HTML5 security'''&amp;lt;br /&amp;gt;&lt;br /&gt;
HTML5 was specially designed to deliver rich content without the need for additional plugins. The current version delivers everything from animation to graphics, music to movies, and can also be used to build complicated web applications. Through introducing these new features new vulnerabilities are introduced as well.&lt;br /&gt;
&lt;br /&gt;
This talk will give an introduction about HTML5 and its new features. Then will select a number of examples to demonstrate the positive, and negative impact of these features for web application security.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
Event gifts sponsored by [http://www.security-meter.com SecurityMeter] and [http://www.zinad.net ZINAD]&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
===== Chapter Strategic Meeting (6 May 2014) ===== &lt;br /&gt;
&lt;br /&gt;
This meeting will focus on preparing the chapter activities plan. (2 hours meeting with no educational sessions)&amp;lt;br /&amp;gt; &lt;br /&gt;
The meeting will be limited for Egyptian AppSec experts only &amp;lt;br /&amp;gt;&lt;br /&gt;
During this meeting, we will discus (in details) the chapter participation in the application security awareness program (determine the joined resources, selecting workshops materials ..... )&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
If anyone is interested, please contact the chapter leader [mailto:mohamed.alfateh@owasp.org Mohamed Alfateh]&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
[[File:Event_Logo.png|thumb|400px]]&lt;br /&gt;
&lt;br /&gt;
==== OWASP-Egypt Event (12 April 2014)==== &lt;br /&gt;
===== Event Presentations ===== &lt;br /&gt;
[[:File:1 OWASP Egypt 12 4 2014 Ahmed Mashaly.ppt|Eg-CERT Cyber security Awareness Team [Ahmed Mashaly]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:2 OWASP Egypt 12 4 2014 Fady Othman.ppt|Living at 21 programmers’ st. Pitfalls in code review [Fady Othman]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:3 OWASP Egypt 12 4 2014 Anwar Mohamed.ppt|OWASP SRDF Project [Anwar Mohamed]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:4 OWASP Egypt 12 4 2014 Ebrahim Hegazy.ppt|Yahoo Zero Day Vulnerability - Code Point of View [Ebrahim Hegazy]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:5 OWASP Egypt 12 4 2014 Ahmed Saafan.ppt|OWASP Lab Projects Overview [Ahmed Saafan]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:6 OWASP Egypt 12 4 2014 Hassan Elhadary.ppt|OWASP Flagship Projects Overview [Hassan Elhadary]]]&amp;lt;br /&amp;gt;&lt;br /&gt;
[[:File:OWASP Egypt 12 4 2014 Mohamed Alfateh.pdf|OWASP Egypt Chapter - Introduction [Mohamed Alfateh]]]&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This event will focus on introducing OWASP to our local community, organizing the chapter contribution and planning the 2014 chapter activities. &amp;lt;br /&amp;gt;&lt;br /&gt;
The event will be hold on the second Saturday of April (12/4/2014) at EBI (Egyptian Banking Institute) &amp;lt;br /&amp;gt; &lt;br /&gt;
Meeting Agenda &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
10:00 – 10: 30 OWASP Egypt Chapter - Introduction (By: '''Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
10:30 – 11:00 Egypt Cert Application Security Awareness Program (By: '''Ahmed Mashaly''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:00 – 11:30 US AppSec Conference 2013 – Brief about some Interesting Topics(By: '''Mostafa Siraj''')&amp;lt;br /&amp;gt;&lt;br /&gt;
11:30 – 12:00 OWASP Security Research and Development Framework(By: '''Anwar Mohamed''')&amp;lt;br /&amp;gt;&lt;br /&gt;
12:00 – 12:30 Break&amp;lt;br /&amp;gt;&lt;br /&gt;
12:30 – 01:00 Effective Bug Hunting for Open Source Applications (By: '''Fady Othman''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:00 – 01:30 Yahoo Zero-Day Vulnerability - Code Point of View(By: '''Ibrahim Hegazy''')&amp;lt;br /&amp;gt;&lt;br /&gt;
01:30 – 02:45 OWASP Projects - Overview(By: '''Ahmed Saafan, Hassan Alhadary and Mohamed Alfateh''')&amp;lt;br /&amp;gt;&lt;br /&gt;
02:45 – 04:00 Panel Discussion: Information Security Challenges, from Individual Privacy to National Security. (Session moderator: '''Adel Abdel Moneim''')&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
-------------------------------------------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:black&amp;quot;&amp;gt;WELCOME MANSOURA!&amp;lt;/span&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
As of 11 September 2011, there is now a new OWASP Chapter in [[Mansoura]], Egypt. The chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil]. [[Mansoura| Click here]] to learn more about what is going on in Mansoura! OR [http://lists.owasp.org/mailman/listinfo/owasp-Mansoura Click here] to view or subscribe to the Mansoura mailing list. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can Download the OWASP LiveCD presentation [http://www.owasp.org/images/1/1f/Owasp_Live_CD-jAN09.pptx HERE] ( Presented @ OWASP - Alexandria Meeting and QCERT Event ) January 2009&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Live CD'''&lt;br /&gt;
&lt;br /&gt;
Qatar,January 27th , OWASP Egypt Presented a live DEMO of the OWASP Live CD During the Qatar Chapter Meetings, More than 60 Copies of the Live CD were distributed to the delegates of Carnegie Mellon Qatar and Qatar University [http://www.qcert.org/news/OWASP_Jan09mtg.html Press Release] , A copy of the Presentation Can be Found HERE.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Presents on the OWASP Initiatives'''&lt;br /&gt;
&lt;br /&gt;
Alexandria,Egypt 12th of February 2009, &lt;br /&gt;
OWASP Egypt presented (Introduction to OWASP Initiatives ) to the IT staff of 2 prominent Oil&amp;amp;Gas Companies&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''OWASP-Egypt Holds a Presentation in Qatar'''&lt;br /&gt;
&lt;br /&gt;
Doha,Qatar 24th of February 2008 , OWASP-Egypt participated in a web security awareness session held in Qatar Sponsored by the country's national CERT team.&lt;br /&gt;
&lt;br /&gt;
the delegates were briefed on OWASP and its objectives, the role OWASP-Egypt chapter is playing in promoting web security best practices in the local IT community and our personal experience on how Qatar can start its very own OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
With the amount of enthusiasm we felt we are expecting a new chapter in the region very soon !&lt;br /&gt;
&lt;br /&gt;
==== Egypt OWASP Chapter Leaders ====&lt;br /&gt;
&lt;br /&gt;
The [[Alexandria]] Chapter Leader is [Mailto:tamer.elzayyat@owasp.org Tamer Elzayyat].&lt;br /&gt;
&lt;br /&gt;
The [[Cairo]] chapter leader is [mailto:Mohamed.Alfateh@owasp.org Mohamed Alfateh].&lt;br /&gt;
&lt;br /&gt;
The [[Mansoura]] chapter leader is [mailto:ahmed.neil@owasp.org Ahmed Neil].&lt;br /&gt;
&lt;br /&gt;
The [[Sohag]] chapter leader position is open. Please visit the [http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing Volunteer Page] to request a chapter restart.&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
[[Category:Africa]]&lt;br /&gt;
[[Category:Egypt]]&lt;/div&gt;</summary>
		<author><name>Mohamed Alfateh</name></author>	</entry>

	</feed>