<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rafael+Dreher</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rafael+Dreher"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Rafael_Dreher"/>
		<updated>2026-05-01T12:48:46Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Rafael_Dreher&amp;diff=167413</id>
		<title>User:Rafael Dreher</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Rafael_Dreher&amp;diff=167413"/>
				<updated>2014-02-05T12:08:47Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;First of all, Rafael Dreher is an Application Security enthusiast. I'm the co-founder of [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre] chapter, along with [[User:Gustavo Barbato|Gustavo Barbato]].&lt;br /&gt;
&lt;br /&gt;
I hold a BS in Information Security, and my main research field is application security, agile software development security and security development lifecycle (SDL) process improvement.&lt;br /&gt;
&lt;br /&gt;
Possessing developed skills that have been gained through establishing and developing full IT security projects, networks and infrastructures from initial conception to completion in Brazilian financial institution. My experience covers security analysis, source code security review, vulnerability assessments, penetration testing, risk analysis, assistance in developing a network and computer security policy and developing a security oriented software development methodology. I have experience programming in languages such as C, C++, Java, script languages as Bash, Perl and others.&lt;br /&gt;
&lt;br /&gt;
Nowadays, I'm a Software Security Engineer at HP.&lt;br /&gt;
&lt;br /&gt;
Contact: dreher 'at' owasp 'dot' org&lt;br /&gt;
&lt;br /&gt;
More info: [http://br.linkedin.com/in/rafaeldreher]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Rafael_Dreher&amp;diff=167412</id>
		<title>User:Rafael Dreher</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Rafael_Dreher&amp;diff=167412"/>
				<updated>2014-02-05T12:07:17Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;First of all, Rafael Dreher is an Application Security enthusiast. I'm the co-founder of [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre] chapter, along with [[User:Gustavo Barbato|Gustavo Barbato]].&lt;br /&gt;
&lt;br /&gt;
I hold a BS in Information Security, and my main research field is application security, agile software development security and security development lifecycle (SDL) process improvement.&lt;br /&gt;
&lt;br /&gt;
Possessing developed skills that have been gained through establishing and developing full IT security projects, networks and infrastructures from initial conception to completion in Brazilian financial institution. My experience covers security analysis, source code security review, vulnerability assessments, penetration testing, risk analysis, assistance in developing a network and computer security policy and developing a security oriented software development methodology&lt;br /&gt;
I also have experience programming in languages such C, C++, Java, script languages as Bash, Perl and others.&lt;br /&gt;
&lt;br /&gt;
Nowadays, I'm a Software Security Engineer at HP.&lt;br /&gt;
&lt;br /&gt;
Contact: dreher 'at' owasp 'dot' org&lt;br /&gt;
&lt;br /&gt;
More info: [http://br.linkedin.com/in/rafaeldreher]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=118387</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=118387"/>
				<updated>2011-10-02T02:24:02Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training) &lt;br /&gt;
[http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Requisitos''':&lt;br /&gt;
Notebook/desktop com VMware/VMplayer instalado, pois será utilizada uma imagem de máquina virtual disponibilizada pelo instrutor.&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugues&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Wagner Elias&lt;br /&gt;
&lt;br /&gt;
'''Requisitos''':&lt;br /&gt;
Notebook/desktop com VMware/VMplayer instalado, pois será utilizada uma imagem de máquina virtual disponibilizada pelo instrutor.&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
 &lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
 &lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutorr''':&lt;br /&gt;
 &lt;br /&gt;
Wagner Elias tem ampla experiência na condução de projetos em IT Security com projetos desenvolvidos em empresas dos mais diversos segmentos. É fundador do capítulo brasileiro da OWASP (Open Web Application Security Project); ocupou o cargo de diretor de conteúdo na gestão 2006-2008 e de eventos da gestão 2008-2010 do capítulo brasileiro da ISSA (Information System Security Association). É co-fundador e sócio da Conviso Application Security, onde atua como CTO (Chief Technical Officer), responsável pela gestão de pesquisa e desenvolvimento de projetos de consultoria em segurança de aplicações. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java. - CANCELADO'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; OWASP &amp;quot;Where we are.. Where we are going&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; You Are Not Amy Winehouse: A New Plan for Reaching the Developer Community&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; Dosh4vulns -- Google's vulnerability reward programs&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Magno Logan'''&amp;lt;br&amp;gt; Segurança em Sites de Compras Coletivas: Economizando dor de cabeça!&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; Caipirinha Security Recipe&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Guia de Estacionamento: http://www3.pucrs.br/portal/page/portal/pucrs/Capa/Noticias?p_itemid=5763486&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Mapapuc.jpg‎|link=https://maps.google.com/maps?q=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;hl=en&amp;amp;ie=UTF8&amp;amp;ll=-30.059818,-51.175185&amp;amp;spn=0.007717,0.009645&amp;amp;sll=-30.059251,-51.172364&amp;amp;sspn=0.007717,0.009645&amp;amp;vpsrc=6&amp;amp;hq=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;t=h&amp;amp;z=17]] &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio501.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio503.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio502.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
[http://www.clicrbs.com.br/zerohora/swf/especial_passeio_poa/index.html Um passeio pela capital]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Climatempo.png|link=http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs]] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Fonte: [http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs Climatempo]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE''' (Hotel oficial do evento) &amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
E-mail: H3258-RE@accor.com.br&lt;br /&gt;
Táxi cootaero do aeroporto para o Novotel: R$30,00 (3358-2500)&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
'''Free transfer Novotel - PUC - Novotel'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Food  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Restaurant Panorama Gastronômico'''&amp;lt;br&amp;gt;&lt;br /&gt;
5% off to OWASP AppSecLatin America 2011 participants&amp;lt;br&amp;gt;&lt;br /&gt;
Avenida Ipiranga, 6681 - prédio 41, 4º andar, PUC-RS&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Jardim Botânico&amp;lt;br&amp;gt;&lt;br /&gt;
CEP: 90619900&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: 3339-2446&amp;lt;br&amp;gt;&lt;br /&gt;
Sits: 650 lugares&amp;lt;br&amp;gt;&lt;br /&gt;
Open at: 11h15/14h (close sunday)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.panoramagastronomico.com.br http://www.panoramagastronomico.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
== Wednesday - 05th october ==&lt;br /&gt;
Dinner (starts 19:30h) at CTG 35 with dance presentation at 21:00.&lt;br /&gt;
Oficial Site: [http://www.35ctg.com.br http://www.35ctg.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sunday - 09th october ==&lt;br /&gt;
'''Sugestions:'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
In the morning: '''City Tour''' (R$ 15 reais)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285 http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285]&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
Lunch: '''Restaurante Costela no Rolete'''&amp;lt;br&amp;gt;&lt;br /&gt;
Rua Marcílio Dias, 965&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Menino Deus&amp;lt;br&amp;gt;&lt;br /&gt;
ZIP: 90130001&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: 3235-1896 e 3061-2155&amp;lt;br&amp;gt;&lt;br /&gt;
Sits: 96 sits&amp;lt;br&amp;gt;&lt;br /&gt;
Schedule: 11h30/15h e 18h30/0h (sáb. e dom. só almoço; fecha seg.)&amp;lt;br&amp;gt;&lt;br /&gt;
R$ 26,00/person&amp;lt;br&amp;gt;&lt;br /&gt;
Especialty: Costela 12hs&amp;lt;br&amp;gt;&lt;br /&gt;
[http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395 http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395]&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Afternoon: &lt;br /&gt;
'''Soccer: Inter vs Vasco'''&amp;lt;br&amp;gt; &lt;br /&gt;
16 hs, Beira-Rio Stadium&amp;lt;br&amp;gt;&lt;br /&gt;
Valid for Brazilian Soccer Championship&amp;lt;br&amp;gt;&lt;br /&gt;
http://www.cdn2.180graus.com/imagem_ca8b12eb8c.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logoglobo.png|link=http://www.globo.com]] &amp;amp;nbsp; [[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp; [[Image:LogoSymantec.png|link=http://www.symantec.com]] &amp;amp;nbsp; [[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg|link=http://www.clavis.com.br]] &amp;amp;nbsp; [[Image:Logosecplusp.png‎|link=http://www.secplus.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tradução Simultanea  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Traduzca.png‎|link=http://http://www.traduzca.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Apoio Institucional ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Csa_br.jpg‎|200px|link=http://br.cloudsecurityalliance.org]] &amp;amp;nbsp; [[Image:Sucesurs.png‎|link=http://www.rs.sucesu.org.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt;  &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://www.appseclatam.org Gustavo Simon]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Leonardo Goldim]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Luiz Gava]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Sarah Baso]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=118386</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=118386"/>
				<updated>2011-10-02T02:23:27Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training). [http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Requisitos''':&lt;br /&gt;
Notebook/desktop com VMware/VMplayer instalado, pois será utilizada uma imagem de máquina virtual disponibilizada pelo instrutor.&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security''' &lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Wagner Elias&lt;br /&gt;
&lt;br /&gt;
'''Requisitos''':&lt;br /&gt;
Notebook/desktop com VMware/VMplayer instalado, pois será utilizada uma imagem de máquina virtual disponibilizada pelo instrutor.&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
 &lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
 &lt;br /&gt;
Hands on&lt;br /&gt;
 &lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
 &lt;br /&gt;
Wagner Elias tem ampla experiência na condução de projetos em IT Security com projetos desenvolvidos em empresas dos mais diversos segmentos. É fundador do capítulo brasileiro da OWASP (Open Web Application Security Project); ocupou o cargo de diretor de conteúdo na gestão 2006-2008 e de eventos da gestão 2008-2010 do capítulo brasileiro da ISSA (Information System Security Association). É co-fundador e sócio da Conviso Application Security, onde atua como CTO (Chief Technical Officer), responsável pela gestão de pesquisa e desenvolvimento de projetos de consultoria em segurança de aplicações. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java. - CANCELADO'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Agenda 06 de Outubro''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Credenciamento'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; OWASP &amp;quot;Where we are.. Where we are going&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; You Are Not Amy Winehouse: A New Plan for Reaching the Developer Community&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; Dosh4vulns -- Google's vulnerability reward programs&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Magno Logan'''&amp;lt;br&amp;gt; Segurança em Sites de Compras Coletivas: Economizando dor de cabeça!&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento do primeiro dia'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Agenda 07 de Outubro''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Credenciamento'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; Caipirinha Security Recipe&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Guia de Estacionamento: http://www3.pucrs.br/portal/page/portal/pucrs/Capa/Noticias?p_itemid=5763486&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Mapapuc.jpg‎|link=https://maps.google.com/maps?q=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;hl=en&amp;amp;ie=UTF8&amp;amp;ll=-30.059818,-51.175185&amp;amp;spn=0.007717,0.009645&amp;amp;sll=-30.059251,-51.172364&amp;amp;sspn=0.007717,0.009645&amp;amp;vpsrc=6&amp;amp;hq=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;t=h&amp;amp;z=17]] &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio501.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio503.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio502.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
[http://www.clicrbs.com.br/zerohora/swf/especial_passeio_poa/index.html Um passeio pela capital]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Climatempo.png|link=http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs]] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Fonte: [http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs Climatempo]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE''' (Hotel oficial do evento) &amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
E-mail: H3258-RE@accor.com.br&lt;br /&gt;
Táxi Cootaero do aeroporto para o Novotel: R$30,00 (3358-2500)&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
'''Haverá Van para traslado Novotel - PUC - Novotel'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Alimentação  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Restaurante Panorama Gastronômico'''&amp;lt;br&amp;gt;&lt;br /&gt;
5% de desconto para os participantes do OWASP AppSecLatin America 2011&amp;lt;br&amp;gt;&lt;br /&gt;
Avenida Ipiranga, 6681 - prédio 41, 4º andar, PUC-RS&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Jardim Botânico&amp;lt;br&amp;gt;&lt;br /&gt;
CEP: 90619900&amp;lt;br&amp;gt;&lt;br /&gt;
Telefone: 3339-2446&amp;lt;br&amp;gt;&lt;br /&gt;
Lugares: 650 lugares&amp;lt;br&amp;gt;&lt;br /&gt;
Horário: 11h15/14h (fecha dom.)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.panoramagastronomico.com.br http://www.panoramagastronomico.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
== Quarta-feira - 05 de outubro ==&lt;br /&gt;
Jantar (a partir das 19:30h) no CTG 35 com apresentação de dança às 21h.&lt;br /&gt;
Site oficial: [http://www.35ctg.com.br http://www.35ctg.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Domingo - 09 de outubro ==&lt;br /&gt;
'''Sugestões:'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Pela manhã: '''City Tour''' (R$ 15 reais)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285 http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
Almoço: '''Restaurante Costela no Rolete'''&amp;lt;br&amp;gt;&lt;br /&gt;
Rua Marcílio Dias, 965&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Menino Deus&amp;lt;br&amp;gt;&lt;br /&gt;
CEP: 90130001&amp;lt;br&amp;gt;&lt;br /&gt;
Telefone: 3235-1896 e 3061-2155&amp;lt;br&amp;gt;&lt;br /&gt;
Lugares: 96 lugares&amp;lt;br&amp;gt;&lt;br /&gt;
Horário: 11h30/15h e 18h30/0h (sáb. e dom. só almoço; fecha seg.)&amp;lt;br&amp;gt;&lt;br /&gt;
R$ 26,00 por pessoa&amp;lt;br&amp;gt;&lt;br /&gt;
Especialidade: Costela 12hs&amp;lt;br&amp;gt;&lt;br /&gt;
[http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395 http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395]&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Pela tarde: &lt;br /&gt;
'''Futebol: Jogo do Inter vs Vasco'''&amp;lt;br&amp;gt; &lt;br /&gt;
16 hs, Estádio Beira-Rio&amp;lt;br&amp;gt;&lt;br /&gt;
Partida válida pelo campeonato brasileiro de futebol&amp;lt;br&amp;gt;&lt;br /&gt;
http://www.cdn2.180graus.com/imagem_ca8b12eb8c.jpg&lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logoglobo.png|link=http://www.globo.com]] &amp;amp;nbsp; [[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp; [[Image:LogoSymantec.png|link=http://www.symantec.com]] &amp;amp;nbsp; [[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &amp;amp;nbsp; [[Image:Logosecplusp.png‎|link=http://www.secplus.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Tradução Simultânea  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Traduzca.png‎|link=http://http://www.traduzca.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Apoio Institucional ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Csa_br.jpg‎|200px|link=http://br.cloudsecurityalliance.org]] &amp;amp;nbsp; [[Image:Sucesurs.png‎|link=http://www.rs.sucesu.org.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt;  &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Gustavo Simon]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Leonardo Goldim]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Luiz Gava]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Sarah Baso]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=118385</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=118385"/>
				<updated>2011-10-02T02:22:06Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training) [http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Requisites''':&lt;br /&gt;
Notebook/desktop with VMware/VMplayer, because one virtual machine image will be used by the instructor.&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security''' &lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Wagner Elias&lt;br /&gt;
&lt;br /&gt;
'''Requisites''':&lt;br /&gt;
Notebook/desktop with VMware/VMplayer, because one virtual machine image will be used by the instructor.&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
 &lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
 &lt;br /&gt;
Hands on&lt;br /&gt;
 &lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
 &lt;br /&gt;
Wagner Elias tem ampla experiência na condução de projetos em IT Security com projetos desenvolvidos em empresas dos mais diversos segmentos. É fundador do capítulo brasileiro da OWASP (Open Web Application Security Project); ocupou o cargo de diretor de conteúdo na gestão 2006-2008 e de eventos da gestão 2008-2010 do capítulo brasileiro da ISSA (Information System Security Association). É co-fundador e sócio da Conviso Application Security, onde atua como CTO (Chief Technical Officer), responsável pela gestão de pesquisa e desenvolvimento de projetos de consultoria em segurança de aplicações. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.''' - '''CANCELED'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; OWASP &amp;quot;Where we are.. Where we are going&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; You Are Not Amy Winehouse: A New Plan for Reaching the Developer Community&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; Dosh4vulns -- Google's vulnerability reward programs&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Magno Logan'''&amp;lt;br&amp;gt; Segurança em Sites de Compras Coletivas: Economizando dor de cabeça!&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; Caipirinha Security Recipe&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Parking guide: http://www3.pucrs.br/portal/page/portal/pucrs/Capa/Noticias?p_itemid=5763486&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Mapapuc.jpg‎|link=https://maps.google.com/maps?q=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;hl=en&amp;amp;ie=UTF8&amp;amp;ll=-30.059818,-51.175185&amp;amp;spn=0.007717,0.009645&amp;amp;sll=-30.059251,-51.172364&amp;amp;sspn=0.007717,0.009645&amp;amp;vpsrc=6&amp;amp;hq=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;t=h&amp;amp;z=17]] &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio501.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio503.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio502.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
[http://www.clicrbs.com.br/zerohora/swf/especial_passeio_poa/index.html Um passeio pela capital]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Climatempo.png|link=http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs]] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Source: [http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs Climatempo]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE''' (Oficial hotel of event) &amp;lt;br&amp;gt; Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
E-mail: H3258-RE@accor.com.br&lt;br /&gt;
Táxi Cootaero from airport to Novotel: R$30,00 ( phone 3358-2500)&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
'''Free transfer Novotel - PUC - Novotel'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Food  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Restaurant Panorama Gastronômico'''&amp;lt;br&amp;gt;&lt;br /&gt;
5% off to OWASP AppSecLatin America 2011 participants&amp;lt;br&amp;gt;&lt;br /&gt;
Avenida Ipiranga, 6681 - prédio 41, 4º andar, PUC-RS&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Jardim Botânico&amp;lt;br&amp;gt;&lt;br /&gt;
CEP: 90619900&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: 3339-2446&amp;lt;br&amp;gt;&lt;br /&gt;
Sits: 650 lugares&amp;lt;br&amp;gt;&lt;br /&gt;
Open at: 11h15/14h (close sunday)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.panoramagastronomico.com.br http://www.panoramagastronomico.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
== Wednesday - 05th october ==&lt;br /&gt;
Dinner (starts 19:30h) at CTG 35 with dance presentation at 21:00.&lt;br /&gt;
Oficial Site: [http://www.35ctg.com.br http://www.35ctg.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sunday - 09th october ==&lt;br /&gt;
'''Sugestions:'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
In the morning: '''City Tour''' (R$ 15 reais)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285 http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285]&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
Lunch: '''Restaurante Costela no Rolete'''&amp;lt;br&amp;gt;&lt;br /&gt;
Rua Marcílio Dias, 965&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Menino Deus&amp;lt;br&amp;gt;&lt;br /&gt;
ZIP: 90130001&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: 3235-1896 e 3061-2155&amp;lt;br&amp;gt;&lt;br /&gt;
Sits: 96 sits&amp;lt;br&amp;gt;&lt;br /&gt;
Schedule: 11h30/15h e 18h30/0h (sáb. e dom. só almoço; fecha seg.)&amp;lt;br&amp;gt;&lt;br /&gt;
R$ 26,00/person&amp;lt;br&amp;gt;&lt;br /&gt;
Especialty: Costela 12hs&amp;lt;br&amp;gt;&lt;br /&gt;
[http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395 http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395]&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Afternoon: &lt;br /&gt;
'''Soccer: Inter vs Vasco'''&amp;lt;br&amp;gt; &lt;br /&gt;
16 hs, Beira-Rio Stadium&amp;lt;br&amp;gt;&lt;br /&gt;
Valid for Brazilian Soccer Championship&amp;lt;br&amp;gt;&lt;br /&gt;
http://www.cdn2.180graus.com/imagem_ca8b12eb8c.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logoglobo.png|link=http://www.globo.com]] &amp;amp;nbsp; [[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp; [[Image:LogoSymantec.png|link=http://www.symantec.com]] &amp;amp;nbsp; [[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &amp;amp;nbsp; [[Image:Logosecplusp.png‎|link=http://www.secplus.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Simultaneous Translation  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Traduzca.png‎|link=http://http://www.traduzca.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Institutional Sponsors ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Csa_br.jpg‎|200px|link=http://br.cloudsecurityalliance.org]] &amp;amp;nbsp; [[Image:Sucesurs.png‎|link=http://www.rs.sucesu.org.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt;  &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Gustavo Simon]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Leonardo Goldim]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Luiz Gava]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Sarah Baso]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=118384</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=118384"/>
				<updated>2011-10-02T02:21:40Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training) [http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Requisites''':&lt;br /&gt;
Notebook/desktop with VMware/VMplayer, because one virtual machine image will be used by the instructor.&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security''' &lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Wagner Elias&lt;br /&gt;
&lt;br /&gt;
'''Requisites''':&lt;br /&gt;
Notebook/desktop with VMware/VMplayer, because one virtual machine image will be used by the instructor.&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
 &lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
 &lt;br /&gt;
Hands on&lt;br /&gt;
 &lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
 &lt;br /&gt;
Wagner Elias tem ampla experiência na condução de projetos em IT Security com projetos desenvolvidos em empresas dos mais diversos segmentos. É fundador do capítulo brasileiro da OWASP (Open Web Application Security Project); ocupou o cargo de diretor de conteúdo na gestão 2006-2008 e de eventos da gestão 2008-2010 do capítulo brasileiro da ISSA (Information System Security Association). É co-fundador e sócio da Conviso Application Security, onde atua como CTO (Chief Technical Officer), responsável pela gestão de pesquisa e desenvolvimento de projetos de consultoria em segurança de aplicações. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.''' - '''CANCELED'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; OWASP &amp;quot;Where we are.. Where we are going&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; You Are Not Amy Winehouse: A New Plan for Reaching the Developer Community&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; Dosh4vulns -- Google's vulnerability reward programs&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Magno Logan'''&amp;lt;br&amp;gt; Segurança em Sites de Compras Coletivas: Economizando dor de cabeça!&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; Caipirinha Security Receipe&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Parking guide: http://www3.pucrs.br/portal/page/portal/pucrs/Capa/Noticias?p_itemid=5763486&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Mapapuc.jpg‎|link=https://maps.google.com/maps?q=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;hl=en&amp;amp;ie=UTF8&amp;amp;ll=-30.059818,-51.175185&amp;amp;spn=0.007717,0.009645&amp;amp;sll=-30.059251,-51.172364&amp;amp;sspn=0.007717,0.009645&amp;amp;vpsrc=6&amp;amp;hq=pucrs+Porto+Alegre+pr%C3%A9dio+50&amp;amp;t=h&amp;amp;z=17]] &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio501.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio503.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Predio502.jpg]]&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
[http://www.clicrbs.com.br/zerohora/swf/especial_passeio_poa/index.html Um passeio pela capital]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Climatempo.png|link=http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs]] &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Source: [http://www.climatempo.com.br/previsao-do-tempo/cidade/363/portoalegre-rs Climatempo]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE''' (Oficial hotel of event) &amp;lt;br&amp;gt; Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
E-mail: H3258-RE@accor.com.br&lt;br /&gt;
Táxi Cootaero from airport to Novotel: R$30,00 ( phone 3358-2500)&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
'''Free transfer Novotel - PUC - Novotel'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Food  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Restaurant Panorama Gastronômico'''&amp;lt;br&amp;gt;&lt;br /&gt;
5% off to OWASP AppSecLatin America 2011 participants&amp;lt;br&amp;gt;&lt;br /&gt;
Avenida Ipiranga, 6681 - prédio 41, 4º andar, PUC-RS&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Jardim Botânico&amp;lt;br&amp;gt;&lt;br /&gt;
CEP: 90619900&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: 3339-2446&amp;lt;br&amp;gt;&lt;br /&gt;
Sits: 650 lugares&amp;lt;br&amp;gt;&lt;br /&gt;
Open at: 11h15/14h (close sunday)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.panoramagastronomico.com.br http://www.panoramagastronomico.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
== Wednesday - 05th october ==&lt;br /&gt;
Dinner (starts 19:30h) at CTG 35 with dance presentation at 21:00.&lt;br /&gt;
Oficial Site: [http://www.35ctg.com.br http://www.35ctg.com.br]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sunday - 09th october ==&lt;br /&gt;
'''Sugestions:'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
In the morning: '''City Tour''' (R$ 15 reais)&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285 http://www2.portoalegre.rs.gov.br/turismo/default.php?p_secao=285]&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
Lunch: '''Restaurante Costela no Rolete'''&amp;lt;br&amp;gt;&lt;br /&gt;
Rua Marcílio Dias, 965&amp;lt;br&amp;gt;&lt;br /&gt;
Bairro: Menino Deus&amp;lt;br&amp;gt;&lt;br /&gt;
ZIP: 90130001&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: 3235-1896 e 3061-2155&amp;lt;br&amp;gt;&lt;br /&gt;
Sits: 96 sits&amp;lt;br&amp;gt;&lt;br /&gt;
Schedule: 11h30/15h e 18h30/0h (sáb. e dom. só almoço; fecha seg.)&amp;lt;br&amp;gt;&lt;br /&gt;
R$ 26,00/person&amp;lt;br&amp;gt;&lt;br /&gt;
Especialty: Costela 12hs&amp;lt;br&amp;gt;&lt;br /&gt;
[http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395 http://vejabrasil.abril.com.br/porto-alegre/restaurantes/costela-no-rolete-29395]&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Afternoon: &lt;br /&gt;
'''Soccer: Inter vs Vasco'''&amp;lt;br&amp;gt; &lt;br /&gt;
16 hs, Beira-Rio Stadium&amp;lt;br&amp;gt;&lt;br /&gt;
Valid for Brazilian Soccer Championship&amp;lt;br&amp;gt;&lt;br /&gt;
http://www.cdn2.180graus.com/imagem_ca8b12eb8c.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logoglobo.png|link=http://www.globo.com]] &amp;amp;nbsp; [[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp; [[Image:LogoSymantec.png|link=http://www.symantec.com]] &amp;amp;nbsp; [[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &amp;amp;nbsp; [[Image:Logosecplusp.png‎|link=http://www.secplus.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Simultaneous Translation  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Traduzca.png‎|link=http://http://www.traduzca.com]]&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Institutional Sponsors ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Csa_br.jpg‎|200px|link=http://br.cloudsecurityalliance.org]] &amp;amp;nbsp; [[Image:Sucesurs.png‎|link=http://www.rs.sucesu.org.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt;  &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Gustavo Simon]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Leonardo Goldim]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Luiz Gava]&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.appseclatam.org Sarah Baso]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116656</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116656"/>
				<updated>2011-09-02T18:13:45Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training). [http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Agenda 06 de Outubro''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Credenciamento'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento do primeiro dia'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Agenda 07 de Outubro''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Credenciamento'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116655</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116655"/>
				<updated>2011-09-02T18:12:44Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training) [http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116654</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116654"/>
				<updated>2011-09-02T18:11:18Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training) &lt;br /&gt;
[http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116653</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116653"/>
				<updated>2011-09-02T18:10:17Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Dinis Cruz  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/6/6c/Dcruz-resized-137.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://uk.linkedin.com/in/diniscruz Dinis Cruz] is a Security Consultant based in London (UK) and specialized in: ASP.NET/J2EE Application Security, Application Security audits and .NET Security Curriculum Development.&lt;br /&gt;
&lt;br /&gt;
For the past couple years Dinis has focused on the field of Static Source Code Analysis and Dynamic Website Assessments (aka penetration testing), and is the main developer of the OWASP O2 Platform which is an Open Source project that is focused on 'Automating Security Consultants Knowledge/Workflows' and 'Allowing non-security experts to access and consume Security Knowledge'. Dinis is currently focused on making the O2 Platform the industry standard for consuming, instrumenting and data-sharing between: the multiple WebAppSec tools, the Security consultants and the final users (from management to developers).&lt;br /&gt;
&lt;br /&gt;
Past industry experience include: running a small Software/Consultancy business, acting as CTO for a Portuguese University, being part of a Security Assessment team (Pentesting and Source Code Assessment) for a global Bank (ABN AMRO), taking the role of Directory of Advanced Technologies at Ounce Labs (acquired by IBM), performing Web Application security assessments on a large number of languages/technologies/frameworks and being a very active participant and enabler at OWASP.&lt;br /&gt;
&lt;br /&gt;
Dinis is an active trainer on .Net security, having written and delivered courses for Ounce Labs, IOActive, Foundstone, Intense School and KPMG (at multiple locations including BlackHat). Dinis has also delivered a number of presentations and keynote speeches at multiple OWASP and Security related conferences.&lt;br /&gt;
&lt;br /&gt;
At OWASP, Dinis is currently the leader of the OWASP O2 Platform project and was previous involved with: OWASP Projects Committee, OWASP Connections Committee and OWASP Foundation Board (were he was been a key driver on a number of major OWASP Initiatives: OWASP Summit 2011 OWASP Seasons of Code, OWASP Summit 2008, OWASP Community building and OWASP Chapter-lead Training) &lt;br /&gt;
&lt;br /&gt;
 [http://uk.linkedin.com/in/diniscruz Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Dcruz-resized-137.jpg&amp;diff=116652</id>
		<title>File:Dcruz-resized-137.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Dcruz-resized-137.jpg&amp;diff=116652"/>
				<updated>2011-09-02T17:45:50Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116651</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116651"/>
				<updated>2011-09-02T17:42:01Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116650</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116650"/>
				<updated>2011-09-02T17:41:04Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Agenda 06 de Outubro''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Credenciamento'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento do primeiro dia'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Agenda 07 de Outubro''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Credenciamento'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116649</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116649"/>
				<updated>2011-09-02T17:40:11Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 6th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tom Brennan'''&amp;lt;br&amp;gt; O que é OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Bryan Sullivan'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rodrigo Montoro'''&amp;lt;br&amp;gt; HTTP Header Hunter - Looking for malicious behavior into your http header traffic&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Alexandre Braga'''&amp;lt;br&amp;gt; Como não escolher a sua senha! Será a senha gráfica o futuro das senhas?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Maximiliano Soler'''&amp;lt;br&amp;gt; Mantra: The Security Framework&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Chris Evans'''&amp;lt;br&amp;gt; TBC&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mushegh Hakhinian'''&amp;lt;br&amp;gt; Strong authentication for online applications: building it right&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Tarcizio Vieira Neto'''&amp;lt;br&amp;gt; Modelo de processo para desenvolvimento de aplicações seguras&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rob Rachwald and Noa Bar-Yosef'''&amp;lt;br&amp;gt; Cyber Vigilantes: How Security Researchers Are Hurting the Business of Hacking&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
== '''Schedule October 7th''' ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:00 – 08:40&lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Registration'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 08:40 – 09:10 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lucas Ferreira'''&amp;lt;br&amp;gt; Segurança na Web: Uma janela de oportunidades&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 09:10 – 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Michael Craigue'''&amp;lt;br&amp;gt; Security Development Lifecycle: A History in 3 Acts&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 – 10:50&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Marcus Hodges'''&amp;lt;br&amp;gt; Highly concurrent Python for brute force and discovery&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 – 11:10&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 11:10 – 12:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Mauro Flores'''&amp;lt;br&amp;gt; Proyectos OWASP para cumplir con PCI&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 12:00 – 12:50&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Silveira'''&amp;lt;br&amp;gt; WAF:FLE, ModSecurity como você nunca viu&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:50 – 14:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 14:20 – 15:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz'''&amp;lt;br&amp;gt; Making Security Invisible by Becoming the Developer's Best Friends&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 – 16:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Wagner Elias'''&amp;lt;br&amp;gt; Automatizando análise passiva de aplicações web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 – 16:20&lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Coffee-Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 – 17:10&lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Rafael Brinhosa'''&amp;lt;br&amp;gt; Segurança de Aplicações, para sua organização ainda não é prioridade?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 – 18:00&lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Breno Silva and Ryan Barnett'''&amp;lt;br&amp;gt; An Innovative Obfuscated Code Analysis Algorithm&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 – 18:30&lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Closing'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116253</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116253"/>
				<updated>2011-08-24T21:01:58Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116252</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116252"/>
				<updated>2011-08-24T21:00:29Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png?|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116251</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116251"/>
				<updated>2011-08-24T20:58:45Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png?|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg?|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116250</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116250"/>
				<updated>2011-08-24T20:57:27Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:PUCRS2.jpg&amp;diff=116249</id>
		<title>File:PUCRS2.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:PUCRS2.jpg&amp;diff=116249"/>
				<updated>2011-08-24T20:54:10Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: uploaded a new version of &amp;amp;quot;File:PUCRS2.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116248</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116248"/>
				<updated>2011-08-24T20:53:39Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:PUCRS2.jpg&amp;diff=116247</id>
		<title>File:PUCRS2.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:PUCRS2.jpg&amp;diff=116247"/>
				<updated>2011-08-24T20:45:16Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: uploaded a new version of &amp;amp;quot;File:PUCRS2.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116246</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116246"/>
				<updated>2011-08-24T20:43:33Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|100px|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png?|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg?|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116245</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116245"/>
				<updated>2011-08-24T20:42:20Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|100px|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116244</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116244"/>
				<updated>2011-08-24T20:40:01Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; &lt;br /&gt;
[[Image:PUCRS2.jpg|100px|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116243</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116243"/>
				<updated>2011-08-24T20:36:45Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &amp;amp;nbsp; [[Image:PUCRS2.jpg|100px|link=http://www.pucrs.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:PUCRS2.jpg&amp;diff=116242</id>
		<title>File:PUCRS2.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:PUCRS2.jpg&amp;diff=116242"/>
				<updated>2011-08-24T20:26:59Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116241</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116241"/>
				<updated>2011-08-24T19:58:55Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, Brasil, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png?|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg?|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116240</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116240"/>
				<updated>2011-08-24T19:57:40Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Capacitación 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Es una capacitación práctica sobre ModSecurity (WAF). Los estudiantes aprenderán los principales temas de ModSecurity, incluyendo instalación, modos de implementación, configuración y registros.&lt;br /&gt;
&lt;br /&gt;
'''1. Qué es ModSecurity?'''&lt;br /&gt;
  *     Cómo instalar&lt;br /&gt;
  *     Arquitecturas&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2. Configurando ModSecurity'''&lt;br /&gt;
  *     Principales directrices de configuración&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3. Personalización de las Reglas'''&lt;br /&gt;
  *     Sintaxis&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principales Variables&lt;br /&gt;
  *     Principales Operadores&lt;br /&gt;
  *     Principales Acciones&lt;br /&gt;
  *     Funciones de Transformación&lt;br /&gt;
  *     Ejercicio 1&lt;br /&gt;
  *     Ejercicio 2&lt;br /&gt;
  *     Ejercicio 3&lt;br /&gt;
  *     Ejercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4. Registro'''&lt;br /&gt;
  *     Extendiendo el Registro&lt;br /&gt;
  *     Ejercicio&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Breno es un científico informático con más de 8 años de experiencia en Tecnología de la Información, con experiencia en una gran variedad de técnicas de desarrollo de software y lenguajes, sistemas de seguridad y tecnologías de red. Breno actualmente es un Investigador de Seguridad del equipo TrustWave Spiderlabs, también el responsable de ModSecurity, miembro del equipo de desarrollo Suricata IDS/IPS. Trabajó en el equipo de respuesta ante incidente para Telecom en América Latina. Breno vive en Brasilia, Brasil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Capacitación 2 - Introducción a la Seguridad de Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Esta capacitación le ayudará a adquirir habilidades sobre la manera de evaluar las aplicaciones desde el punto de vista del hacker, entender las vulnerabilidades de seguridad en aplicaciones y aprender cómo remediar esos agujeros de seguridad en sus aplicaciones Java o .NET y que no sean explotados por un hacker. Este curso intensivo de un día se centra en los problemas seguridad de aplicaciones Web más comunes, incluidos los aspectos de OWASP Top Ten (2010) y el Top 25 de MITRE.&lt;br /&gt;
&lt;br /&gt;
Prácticas: Los estudiantes participarán de varios ejercicios de prueba de seguridad donde ellos atacarán aplicaciones reales (como WebGoat), que ha sido diseñado con diferentes vulnerabilidades y así utilizar Proxies (como Webscarab) para completar el ejercicio.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Fabio actualmente trabaja como Especialista de Seguridad de la Información en AIB Bank (Dublin, Irlanda). Sus tareas incluyen el análisis de riesgos, evaluación de seguridad de aplicaciones Web desarrolladas internamente o adquiridas a terceros, definición de políticas y normas de código seguro, como así también la capacitación en seguridad de aplicaciones Web para desarrolladores, auditores, ejecutivos y profesionales de la seguridad. Antes de ingresar al AIB, trabajó como Ingeniero de Seguridad en el Symantec Security Response analizando código malicioso, amenazas, riesgos de seguridad y vulnerabilidades en varias aplicaciones. Antes de transladarse a Irlanda, trabajó en el desarrollo de diferentes programas de capacitación y actividades que apoyaban el desarrollo de software seguro en Argentina, su país de origen. Como miembro de OWASP, Fabio es parte del Comité de Educación Global cuya misión es proveer servicios de educación y capacitación a empresas, gobiernos e instituciones educativas en seguridad de aplicaciones; él coordina las conferencias internacionales en relación a este tema; y desde el 2010 es el líder del Capítulo de OWASP en Irlanda. Fabio está graudado en Ingeniería en Informática por la Universidad Católica Argentina y ha obtenido la certificación CISSP por (ISC) 2 en el 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Capacitación 3 - Introducción a la Criptografía ilustrada en Java para Desarrolladores Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 05 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La criptografía es la única tecnología capaz de proteger los datos en tránsito. A criptografia é a única tecnologia capaz de proteger dados em trânsito. El mimicurso tendrá contenido de carácter general: cifrado simétrico, cifrado asimétrico, modos de operación de cifrado de bloques, las funciones hash, funciones MAC, generadores pseudo-aleatorios de números y protocolos de acuerdo clave y SSL. Ya que es un capacitación para programadores, todo el contenido se ejemplifica en Java y se hará hincapié en la identificación de mal uso de la criptografía. El curso tiene foco en lo práctico y no sólo en las presentaciones (PPT).&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesor Universitario de Tecnología y Seguridad por 10 años.&lt;br /&gt;
Profesor Universitario de Desarrollo Seguro de Software y Criptografía por 5 años.&lt;br /&gt;
Autor de numerosos artículos científicos.&lt;br /&gt;
Instructor de capacitaciones para diversas organizaciones privadas de Brasil y del exterior, como así también instituciones educativas.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Capacitación 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
El objetivo de esta capacitación es brindar una comprensión correcta sobre el Top 10 de los principales riesgos en Aplicaciones Web usando el documento OWASP Top 10 v.2010, que describe a estos, su impacto y cómo evitarlos. Pasaremos por los 10 riesgos, mostrando ejemplos prácticos y su explicación detallada. Los estudiantes tendrán la oportunidad de practicar investigando y corrigiendo estas vulnerabilidades con WebGoat, el cual también es un Proyecto de OWASP desarrollado en Java EE. Todos los ejemplos serán en Java, por lo tanto un conocimiento en este lenguaje es una ventaja, pero no obligatorio.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira es el líder y fundador del Capítulo de OWASP Paraíba. Postgrado en Seguridad de la Información por la Facultad de Tecnología de Joao Pessoa. Realizó un curso de 1 (un) año en Informática Forense en Nueva York, EEUU. Título en Sistemas Tecnológicos para Internet por el Instituto Federal de Educación, Ciencia y Tecnología de Paraíba. Actualmente se desempeña como Analista de Sistemas de Politec, para la Secretaría de Hacienda de Estado en Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Capacitación 5 - Protegiendo Aplicaciones Web Java contra vulnerabilidades conocidas (y desconocidas) con el nuevo Mod_Security para Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Español&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
Explicación sobre cómo funciona Mod_Security para Java, cuándo es conveniente utilizarlo, cómo instalarlo, configurarlo y crear reglas en XML y formato Mod_Security para proteger aplicaciones java contra vulnerabilidades del OWASP Top 10 y SANS/CWE 25. También una introducción a OWASP Mod_Security Core Ruleset para proteger aplicaciónes sobre posibles patrones que puedan exponer nuevas vulnerabilidades.&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Profesional con 11 años de experiencia en Seguridad de Apliciones, trabajando para empresas multinacionales en sectores financieros, aviación, medios de comunicación y transporte, participa en OWASP como líder de proyecto desde hace 5 años y certificado CSSLP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Capacitación 6 - Uso de OWASP ESAPI (Enterprise Security API) para Proporcionar Seguridad en Aplicaciones Web'''&lt;br /&gt;
&lt;br /&gt;
'''Fecha:''' 04 de Octubre de 2011 - 9h hasta las 17:30 h&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Portugués&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumen''':&lt;br /&gt;
La evolución de la tecnología en el desarrollo de aplicaciones Web ha contribuido a un aumento significativo en el uso de esta tecnología para satisfacer los más diversos propósitos. Sin embargo, esta tecnología está sujeta a varias vulnerabilidades de seguridad críticas, sobre todo cuando las encuestas recientes muestran que la mayoría de las vulnerabilidades están presentes en la propia aplicación.&lt;br /&gt;
La librería ESAPI (Enterprise Security API) de OWASP surge en este escenario, como una librería de código abierto disponible para varios lenguajes como Java EE, PHP, .NET, ASP, Python, Ruby, entre otros. El curso cubre de forma práctica las vulnerabilidades causadas por errores comunes en el desarrollo de aplicaciones y los mecanismos de seguridad proporcionados por la librería ESAPI con un enfoque en Java. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre el Instructor''':&lt;br /&gt;
Tarcizio Vieira Neto es Licenciado en Ciencias de la Computación de la Universidad Federal de Goiás (UFG), Goiânia. Actualmente trabaja en SERPRO desde noviembre de 2009, como Analista de Desarrollo, Coordinación Estratégica de Tecnología CETEC, focalizando su trabajo en el desarrollo seguro de aplicaciones, aspectos técnicos y de procedimientos, como así también en la investigación de herramientas para el desarrollo seeguro de aplicaciones Web.&lt;br /&gt;
También ha participado como instructor en la capacitación de nuevos empleados y la asistencia en la preparación del material del curso en Educación a Distancia en la Universidad SERPRO (UniSERPRO).&lt;br /&gt;
Participó en la primera versión de la traducción de OWASP Secure Coding Principles Quick Reference Guide para Portugués (BR) y lideró el proyecto de revisión del mismo documento.&lt;br /&gt;
Cuenta con experiencia en Gestión de Seguridad de la Información de la Universidad de Brasilia (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
La conferencia será en Porto Alegre, Rio Grande do Sul, en el auditorio del edificio 50 de la [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Ver localización en [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
El formulario de inscripción está disponible en http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Sólo la conferencia:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Septiembre:    350.00 BRL&lt;br /&gt;
* Después de 1 de Octubre:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Capacitaciones'''&lt;br /&gt;
&lt;br /&gt;
* Un (1) día:     450.00 BRL&lt;br /&gt;
* Dos (2) días:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor, consulte el formulario de inscripción para obtener información sobre valores de paquetes de suscripción.''&lt;br /&gt;
&lt;br /&gt;
'''Descuentos'''&lt;br /&gt;
&lt;br /&gt;
* Miembro de OWASP: R$ 100,00 (Nota: Este descuento es mayor que la anual USD 50.00. Compruébelo [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudiantes: R$ 100.00 (Nota: Será necesario presentar comprobante de matrícula	).&lt;br /&gt;
* Descuentos especiales para grupos, por favor póngase en contacto con nosotros por correo electrónico appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png?|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg?|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116239</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116239"/>
				<updated>2011-08-24T19:52:44Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at [http://www.pucrs.br PUCRS University] - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116238</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116238"/>
				<updated>2011-08-24T19:48:51Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da [http://www.pucrs.br PUCRS].&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116237</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116237"/>
				<updated>2011-08-24T19:47:18Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Local ====&lt;br /&gt;
&lt;br /&gt;
A conferência será em Porto Alegre, Rio Grande do Sul, no auditório do prédio 50 da PUCRS.&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116236</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116236"/>
				<updated>2011-08-24T19:42:50Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at PUCRS University - Building 50 Auditorium.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116235</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116235"/>
				<updated>2011-08-24T19:40:11Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
The event will be held in Porto Alegre, RS, Brazil at PUCRS University.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com.br/maps?oe=utf-8&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a&amp;amp;um=1&amp;amp;hl=en&amp;amp;biw=1440&amp;amp;bih=760&amp;amp;ie=UTF-8&amp;amp;q=PUCRS&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=PUCRS&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+Rio+Grande+do+Sul&amp;amp;cid=0,0,13248223140037344003&amp;amp;ei=y1JVTq7yBaOtsQLS6Im3Bw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;ved=0CAQQ_BI Google Maps] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116119</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116119"/>
				<updated>2011-08-23T00:19:48Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116118</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116118"/>
				<updated>2011-08-23T00:19:19Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116117</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116117"/>
				<updated>2011-08-23T00:18:47Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://registration2011.appseclatam.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116115</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116115"/>
				<updated>2011-08-22T17:42:59Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116114</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116114"/>
				<updated>2011-08-22T17:41:57Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Descontos'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116113</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116113"/>
				<updated>2011-08-22T17:39:37Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to appsec2011@appseclatam.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116112</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116112"/>
				<updated>2011-08-22T17:38:27Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
O formulário de inscrição está disponível em http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Valores  ==&lt;br /&gt;
&lt;br /&gt;
'''Apenas a conferência:'''&lt;br /&gt;
&lt;br /&gt;
* Antes de 31 de Agosto:        250.00 BRL&lt;br /&gt;
* Antes de 30 de Setembro:    350.00 BRL&lt;br /&gt;
* Depois de 1 de Outubro:      450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Treinamentos'''&lt;br /&gt;
&lt;br /&gt;
* Um (1) dia:     450.00 BRL&lt;br /&gt;
* Dois (2) dias:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Por favor verifique o formulário de inscrições para informações sobre valores de pacotes de inscrição''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* Membro do OWASP: R$ 100,00 (Nota: Este desconto é maior do que a taxa anual de USD 50.00. Confira [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1 aqui]&lt;br /&gt;
* Estudantes: R$ 100.00 (Nota: Será necessário apresentar comprovante de matrícula).&lt;br /&gt;
* Descontos especiais para grupos: entre em contato conosco pelo email appsec2011@appseclatam.org&lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116111</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116111"/>
				<updated>2011-08-22T17:32:23Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Online Registration ==&lt;br /&gt;
&lt;br /&gt;
Registration form is available at http://appseclatam2011-registration.poasec.org/&lt;br /&gt;
&lt;br /&gt;
== Conference Fees  ==&lt;br /&gt;
&lt;br /&gt;
'''Access to conference:'''&lt;br /&gt;
&lt;br /&gt;
* Before Aug 31st:  250.00 BRL&lt;br /&gt;
* Before Sep 30th:  350.00 BRL&lt;br /&gt;
* After Oct 1st:       450.00 BRL&lt;br /&gt;
&lt;br /&gt;
'''Trainings'''&lt;br /&gt;
&lt;br /&gt;
* One day:    450.00 BRL&lt;br /&gt;
* Two days:  900.00 BRL&lt;br /&gt;
&lt;br /&gt;
''Please check the registration form for information about conference packages.''&lt;br /&gt;
&lt;br /&gt;
'''Discounts'''&lt;br /&gt;
&lt;br /&gt;
* OWASP Member:  100.00 BRL (Note: This discount is greater than the OWASP USD 50.00 annual fee. Check [http://www.google.com.br/#q=50+usd+in+brl&amp;amp;fp=1  here]&lt;br /&gt;
* Student:              100.00 BRL (Note: student ID required).&lt;br /&gt;
* Special discounts available for groups registrations. Please send inquiries to organizacao2010@appsecbrasil.org&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116106</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116106"/>
				<updated>2011-08-22T13:57:19Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
=== Costo de Registro  ===&lt;br /&gt;
&lt;br /&gt;
Será publicado a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116105</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116105"/>
				<updated>2011-08-22T13:55:34Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
=== Registration Fees  ===&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116104</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116104"/>
				<updated>2011-08-22T13:53:43Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
=== Preços ===&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116042</id>
		<title>AppSecLatam2011 (es)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(es)&amp;diff=116042"/>
				<updated>2011-08-21T00:13:30Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Lenguaje:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Prensa] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Menciones de Medios]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Síganos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Bienvenido  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Nos complace en anunciar que el [http://www.owasp.org/index.php/Porto_Alegre Capítulo Local de OWASP Puerto Alegre] organizará '''Global AppSec Latín America 2011 Conference''' en Puerto Alegre-RS, Brasil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
La Global AppSec Latín America 2011 Conference será un encuentro de líderes de América Latína en Seguridad de la Información, donde se presentarán ideas de vanguardia. Los eventos organizados por OWASP atraen a la audiencia interesada en las últimas novedades. Se espera la presencia de 200-250 personas de diferentes ámbitos, Gubernamentales, Servicios Financieros, Medios de Comunicación, Farmacia, Salud, Tecnología, entre otros.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
OWASP Global AppSec Latín América 2011 se realizará en la ciudad de Puerto Alegre, estado de Río Grande del Sur, Brasil [http://maps.google.es/maps?f=q&amp;amp;source=s_q&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa] del 4 a 7 de Octubre de 2011. Las capacitaciones serán 4 y 5, mientras que la conferencia será 6 y 7 de Octubre.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sí usted tiene alguna pregunta, por favor, envíe un email a la organización: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quién debería asistir a Global AppSec Latín América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desarrolladores de Aplicaciones&lt;br /&gt;
*Probadores de Aplicación y Aseguradores de Calidad&lt;br /&gt;
*Administradores de Proyectos y Personal&lt;br /&gt;
*Directores de Seguridad de la Información, Jefes de Tecnología&lt;br /&gt;
*Directores de Finanzas, Auditores, Responsables de Seguridad&lt;br /&gt;
*Administradores de Seguridad&lt;br /&gt;
*Ejecutivos, Gerentes, personal responsable de Gobierno de Seguridad&lt;br /&gt;
*Profesionales de TI interesados en la mejora de la Seguridad&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Utilice el siguiente hashtag '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' para twittear acerca de Global AppSec Latín América 2011 (Qué son los [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Síguenos en Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Lea la LLamada a las Capacitaciones (Call for Trainings) en: [https://www.owasp.org/index.php/AppSecLatam2011/CFT_es https://www.owasp.org/index.php/AppSecLatam2011/CFT_es] &lt;br /&gt;
&lt;br /&gt;
Estamos realizando una investigación sobre los tópicos de las capacitaciones. Usted puede ayudarnos respondiendo las preguntas en la siguiente dirección: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Lea la Llamada a las Presentaciones en [https://www.owasp.org/index.php/AppSecLatam2011/CFP_es https://www.owasp.org/index.php/AppSecLatam2011/CFP_es] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Comité del Programa  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Conferencias Destacadas  ====&lt;br /&gt;
&lt;br /&gt;
== '''Conferencias Destacadas'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] es Investigador Señor de Seguridad en Adobe Systems, donde él está focalizado en cuestiones de seguridad en la nube. Antes de Abobe, trabajó como Director del equipo de Desarrollo Seguro de Microsoft (SDL), y Jefe de Desarrollo en HP, donde ha ayudado a diseñar los escáneres de vulnerabilidades WebInspect y DevInspect.&lt;br /&gt;
Bryan ha sido orador en conferencias de seguridad como Black Hat, RSA Conference, BlueHat y TechEd sobre diversos tópicos incluyendo NoSQL, RIA, REST, Criptografía, Defensa de DoS,  reescritura de URLs, y aplicación de desarrollo seguro a Proyectos Ágiles. Autor de la columna &amp;quot;Security Briefs&amp;quot; en MSDN Magazine, y es el coautor de los libros Ajax Security (Addison-Wesley, 2007) y el próximo a publicarse Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Oradores Invitados'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evans es conocido por varios trabajos en la comunidad de la seguridad. En particular, él es investigador de seguridad y autor de vsftpd. Los detalles de vsftpd pueden encontrarse en http://vsftpd.beasts.org/. Su trabajo incluye vulnerabilidades en los principales navegadores (Firefox, Safari, Internet Explorer, Opera, Chrome); los núcleos de los sistemas operativos Linux y OpenBSD; la JDK de Sun; y varios paquetes de código abierto. Él publica sus trabajos en el Blog [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. En Google, Chris actualmente lidera la seguridad de Google Chrome. Se ha presentado en varias conferencias (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) mientras que en HiTB y WOOT forma parte del panel de selección de los trabajos. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;1000&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) es Director del grupo de Consultoría en Seguridad de Dell, con 14 miembros del equipo en Brasil, India, Malasia, y Estados Unidos. Él y su equipo tienen la responsabilidad de los departamentos internos de Dell incluyendo TI, Grupo de Productos, Servicios, y Funciones y Adquisiciones, con un enfoque particular en el Ciclo de Vida de Desarrollo de Software Seguro. Ha sido profesor en Administración de Base de Datos e Inteligencia Artificial / Gestión del Conocimiento en St. Edward's University en los programas de MBA (Master in Business Administration) / MS CIS (Master of Science in Computer Information Systems). Antes de unirse al equipo de seguridad de la información de Dell, desarrolló por más de una década Aplicaciones Web y de Base de Datos. Tiene un doctorado en la Universidad de Texas en Austin, en Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== 4-5 de Octubre (Capacitaciones)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 6 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== 7 de Octubre  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Registración  ====&lt;br /&gt;
&lt;br /&gt;
Será publicada a la brevedad.&lt;br /&gt;
&lt;br /&gt;
=== Costo de Registro  ===&lt;br /&gt;
&lt;br /&gt;
Será publicado a la brevedad.&lt;br /&gt;
&lt;br /&gt;
==== Información Útil  ====&lt;br /&gt;
&lt;br /&gt;
== Guía para Visitantes  ==&lt;br /&gt;
&lt;br /&gt;
Puerta para turistas en el estado de Rio Grande del Sur en Brasil, y a sólo 200 KM de la agradable Sierra Gaucha, Puerto Alegre tiene un centro de servicios y una infraestructura con calidad reconocida, y una base de grandes empresas nacionales e internacionales junto con una importante cantidad de eventos internacionales en Brasil.&lt;br /&gt;
&lt;br /&gt;
Enlaces útiles: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Informe sobre Brasil y su potencial desarrollo (60 Minutos): &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Video Turístico sobre la Ciudad de Puerto Alegre:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Corriente Eléctrica  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referencia: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Estado del Tiempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viaje  ==&lt;br /&gt;
&lt;br /&gt;
== Alojamiento  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociales  ====&lt;br /&gt;
&lt;br /&gt;
La información será publicada aquí.&lt;br /&gt;
&lt;br /&gt;
==== Patrocinio  ====&lt;br /&gt;
&lt;br /&gt;
Estamos buscando patrocinadores para la edición de Global AppSec América Latína 2011. Ver más detalles sobre oportunidades de patrocinio.&lt;br /&gt;
&lt;br /&gt;
Sí usted está interesado en ser Patrocinador de Global AppSec Latín America 2011, por favor contáctese: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para saber más sobre las oportunidades de patrocinio por favor consulte el siguiente documento: &amp;lt;br&amp;gt; [https://www.owasp.org/images/7/70/OWASP_AppSec_2011_Sponsorship_Spanish.pdf OWASP AppSec 2011 Patrocinio Español.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores kit conferencia  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Promoción Local  ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|Logo-PoaSec.png]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Equipo  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; [http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116041</id>
		<title>AppSecLatam2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011&amp;diff=116041"/>
				<updated>2011-08-21T00:11:31Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Language:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Press Release] &lt;br /&gt;
*[[AppSecLA2011/Media Mentions|Media Mentions]] &lt;br /&gt;
*[[AppSecLA2011/Archived|Archived]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Follow us:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png]&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Porto_Alegre OWASP Porto Alegre Local Chapter] will organize the '''Global AppSec Latin America 2011 Conference''' in Porto Alegre-RS, Brazil. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 map] in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; If you have any questions, please email the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Who Should Attend Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interested in Improving IT Security&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag for your tweets for Global AppSec Latin America 2011 (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Follow us on Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT &amp;amp;amp; CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Trainings in: [https://www.owasp.org/index.php/AppSecLatam2011/CFT https://www.owasp.org/index.php/AppSecLatam2011/CFT] &lt;br /&gt;
&lt;br /&gt;
We are doing a research about subjects of the trainings. You can help us, answering the questions in the follow address: &lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR] &lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Read the Call for Presentations in: [https://www.owasp.org/index.php/AppSecLatam2011/CFP https://www.owasp.org/index.php/AppSecLatam2011/CFP] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Program Committee  ==&lt;br /&gt;
&lt;br /&gt;
*Kuai Hinojosa &lt;br /&gt;
*Leandro Gomes &lt;br /&gt;
*Leonardo Buonsanti &lt;br /&gt;
*Leonardo Lemes &lt;br /&gt;
*Luiz Eduardo &lt;br /&gt;
*Luiz Otávio Duarte &lt;br /&gt;
*Mateo Martinez &lt;br /&gt;
*Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== October 4th-5th (Training)  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
'''Training 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese/English&lt;br /&gt;
&lt;br /&gt;
'''Instructor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Training 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish/English&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Training 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 5th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Training 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese/English&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Training 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Spanish/English&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Training 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Date:''' October 4th 2011 - 9AM to 5:30PM&lt;br /&gt;
&lt;br /&gt;
'''Language:''' Portuguese&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Abstract''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About the instructor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== October 6th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== October 7th  ====&lt;br /&gt;
&lt;br /&gt;
== Schedule  ==&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
=== Registration Fees  ===&lt;br /&gt;
&lt;br /&gt;
To be published soon. &lt;br /&gt;
&lt;br /&gt;
==== Practical Info  ====&lt;br /&gt;
&lt;br /&gt;
== Visitors' Guide  ==&lt;br /&gt;
&lt;br /&gt;
Gate for tourists in the state of Rio Grande do Sul in Brazil, and only 120 miles from the pleasant Serra Gaucha, Porto Alegre is a bustling hub of services and infrastructure with quality recognized, and a base of large national and international companies and a major destination for international events in Brazil. &lt;br /&gt;
&lt;br /&gt;
Usefull links: &lt;br /&gt;
&lt;br /&gt;
[http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/en/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; 60 Minutes recent report about Brazil and his development potencial: &amp;lt;br&amp;gt; {{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Tourist video about Porto Alegre City:&amp;lt;br&amp;gt; {{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Electric Outlet  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Reference: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Weather  ==&lt;br /&gt;
&lt;br /&gt;
== Trip  ==&lt;br /&gt;
&lt;br /&gt;
== Accommodation  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Phone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Cortesy breakfast&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
General Conditions&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Map link:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Social Events  ====&lt;br /&gt;
&lt;br /&gt;
Information will be published here. &lt;br /&gt;
&lt;br /&gt;
==== Sponsoring  ====&lt;br /&gt;
&lt;br /&gt;
We are looking for sponsors for 2011 edition of Global AppSec Latin America. See more details about sponsor opportunities. &lt;br /&gt;
&lt;br /&gt;
If you are interested to sponsor Global AppSec Latin America 2011, please contact the conference chair: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
To find out more about the different sponsorship opportunities please check the document below: &amp;lt;br&amp;gt; [http://www.owasp.org/images/4/4f/OWASP_AppSec_2011_Sponsorship_English.pdf OWASP AppSec 2011 Sponsorship English.pdf] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Diamond Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
== Gold Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]] &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Silver Sponsors ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Conference Kit Sponsors  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Local Promotion ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Team  ====&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116040</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116040"/>
				<updated>2011-08-20T23:54:41Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
=== Preços ===&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116039</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116039"/>
				<updated>2011-08-20T23:53:53Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 05 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Espanhol/Inglês&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 04 de Outubro de 2011 - 9h até 17h30min&lt;br /&gt;
&lt;br /&gt;
'''Idioma:''' Português&lt;br /&gt;
&lt;br /&gt;
'''Instrutor:''' Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
=== Preços ===&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116038</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116038"/>
				<updated>2011-08-20T23:51:06Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1 - ModSecurity Training'''&lt;br /&gt;
&lt;br /&gt;
'''Data: 05 de Outubro de 2011 - 9h até 17h30min'''&lt;br /&gt;
&lt;br /&gt;
'''Idioma: Português/Inglês''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2 - Introduction to Web Application Security'''&lt;br /&gt;
&lt;br /&gt;
'''Data: 05 de Outubro de 2011 - 9h até 17h30min'''&lt;br /&gt;
&lt;br /&gt;
'''Idioma: Espanhol/Inglês''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 3 - Introdução à criptografia ilustrada em Java para programadores web'''&lt;br /&gt;
&lt;br /&gt;
'''Data: 05 de Outubro de 2011 - 9h até 17h30min'''&lt;br /&gt;
&lt;br /&gt;
'''Idioma: Português''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4 - OWASP Top 10 + Java EE'''&lt;br /&gt;
&lt;br /&gt;
'''Data: 04 de Outubro de 2011 - 9h até 17h30min'''&lt;br /&gt;
&lt;br /&gt;
'''Idioma: Português/Inglês''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 5 - Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.'''&lt;br /&gt;
&lt;br /&gt;
'''Data: 04 de Outubro de 2011 - 9h até 17h30min'''&lt;br /&gt;
&lt;br /&gt;
'''Idioma: Espanhol/Inglês''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
''Treinamento 6 - Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web'''&lt;br /&gt;
&lt;br /&gt;
'''Data: 04 de Outubro de 2011 - 9h até 17h30min'''&lt;br /&gt;
&lt;br /&gt;
'''Idioma: Português''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
=== Preços ===&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116037</id>
		<title>AppSecLatam2011 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecLatam2011_(pt-br)&amp;diff=116037"/>
				<updated>2011-08-20T23:22:25Z</updated>
		
		<summary type="html">&lt;p&gt;Rafael Dreher: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;700&amp;quot; | &lt;br /&gt;
! align=&amp;quot;center&amp;quot; width=&amp;quot;500&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:AppSec Brasil 11 medio.png]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&amp;lt;br&amp;gt; '''Língua:&amp;lt;br&amp;gt;[http://www.owasp.org/index.php?title=AppSecLatam2011 http://www.owasp.org/images/8/88/Bandeira_reino_unido.png]	&lt;br /&gt;
[http://www.owasp.org/index.php?title=AppSecLatam2011_(pt-br) http://www.owasp.org/images/4/49/Bandeira_brasil.png] [http://www.owasp.org/index.php?title=AppSecLatam2011_(es) http://www.owasp.org/images/1/1c/Bandeira_espanha.png]  | &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/images/1/19/AppSecLatam_2011_Announcement.pdf Comunicado de Imprensa] &lt;br /&gt;
*[[AppSecLatam2011/Media Mentions|Menções na mídia]] &lt;br /&gt;
*[[AppSecLatam2011/Archived|Arquivos]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Siga-nos:&amp;lt;br&amp;gt;[http://www.twitter.com/AppSecLatam http://www.owasp.org/images/f/f7/Twitter.png]	&lt;br /&gt;
[http://www.facebook.com/event.php?eid=155195651207509 http://www.owasp.org/images/5/55/Facebook.png] [http://events.linkedin.com/OWASP-Global-AppSec-Latin-America-2011/pub/607738 http://www.owasp.org/images/1/1a/Linkedin.png] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Apresentação  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
Temos o prazer de anunciar que o [http://www.owasp.org/index.php/Porto_Alegre Capítulo OWASP de Porto Alegre] irá organizar a '''Conferência Global AppSec Latin America 2011''' em Porto Alegre-RS, Brasil. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A conferência Global AppSec Latin América 2011 será uma reunião de líderes latino-americanos na área de Segurança da Informação, e irá apresentar temas e idéias de vanguarda sobre o assunto. Eventos OWASP atraem público do mundo todo interessados nas tendências da área. A conferência espera atrair 200 a 250 tecnólogos do governo, serviços financeiros, mídia, indústria farmacêutica, saúde, tecnologia, e muitas outras áreas. &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A OWASP Global AppSec Latin América 2011 irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul ([http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=Porto+Alegre&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Porto+Alegre+-+Rio+Grande+do+Sul,+Brasil&amp;amp;z=11 mapa]) nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Se você tiver algum questionamento, por favor entre em contato com a organização do evento através do e-mail: [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org].&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt; '''Quem deve atender a Global AppSec Latin América 2011:''' &lt;br /&gt;
&lt;br /&gt;
*Desenvolvedores de Aplicativos &lt;br /&gt;
*Testadores de Aplicativos e de Qualidade &lt;br /&gt;
*Gerentes de Projetos de Aplicativos e Funcionários &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputados, Associados and Membros &lt;br /&gt;
*Chief Financial Officers, Auditores, e Pessoas Responsáveis pela Segurança de TI e Compliance &lt;br /&gt;
*Gerentes de Segurança e Pessoal &lt;br /&gt;
*Executivos, Gerentes e Pessoas Responsáveis pela Governança de TI &lt;br /&gt;
*Profissionais de TI Interessados em Aprofundar seus Conhecimentos em Segurança&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Mediawiki needs all these spaces --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[Image:Owasp-poa-eng.png]] &lt;br /&gt;
&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use o '''[http://search.twitter.com/search?q=%23AppSecLatam #AppSecLatam]''' hashtag para seus tweets para a Global AppSec Latin America 2011 (O que é [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@AppSecLatAm Twitter Feed ([http://twitter.com/AppSecLatam Siga-nos no Twitter!])''' &amp;lt;twitter&amp;gt;262394051&amp;lt;/twitter&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== CFT e CFP  ====&lt;br /&gt;
&lt;br /&gt;
== CFT  ==&lt;br /&gt;
Leia a chamada de mini-cursos completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFT].&lt;br /&gt;
&lt;br /&gt;
Estamos realizando uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;
&lt;br /&gt;
[http://www.surveymonkey.com/s/3RCZ9RR http://www.surveymonkey.com/s/3RCZ9RR]&lt;br /&gt;
&lt;br /&gt;
== CFP  ==&lt;br /&gt;
&lt;br /&gt;
Leia a chamada de trabalhos para apresentações completa em [https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP https://www.owasp.org/index.php/AppSecLatam2011_(pt-br)/CFP].&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Comitê de Programa  ==&lt;br /&gt;
&lt;br /&gt;
* Kuai Hinojosa&lt;br /&gt;
* Leandro Gomes&lt;br /&gt;
* Leonardo Buonsanti&lt;br /&gt;
* Leonardo Lemes&lt;br /&gt;
* Luiz Eduardo&lt;br /&gt;
* Luiz Otávio Duarte&lt;br /&gt;
* Mateo Martinez&lt;br /&gt;
* Rodrigo Rubira&lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
== '''Keynotes'''  ==&lt;br /&gt;
&lt;br /&gt;
== Bryan Sullivan  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/3/36/Bryan-sullivan.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/bryanjsullivan Bryan Sullivan ] is a Senior Security Researcher with Adobe Systems, where he focuses on cloud security issues. Prior to Adobe, he was a program manager on Microsoft's Security Development Lifecycle team, and a development manager at HP, where he helped to design HP's vulnerability scanning tools WebInspect and DevInspect. &lt;br /&gt;
Bryan has spoken at security industry conferences such as Black Hat, RSA Conference, BlueHat and TechEd on a diverse range of topics including NoSQL, RIA architecture, REST, cryptography, denial-of-service defense, URL rewriting, and applying secure development processes to Agile projects. He was the author of the MSDN Magazine column Security Briefs, and is the coauthor of the books Ajax Security (Addison-Wesley, 2007) and the upcoming Secure Web Applications, A Beginner's Guide (McGraw-Hill, 2011). [http://www.linkedin.com/in/bryanjsullivan Linkedin] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== '''Guest Speakers'''  ==&lt;br /&gt;
&lt;br /&gt;
== Chris Evans  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/4/48/ChrisEvans1.png &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/scarybeast Chris Evans] - Troublemaker, Google Inc. Chris Evan is known for various work in the security community. Most notably, he is the author of vsftpd and a vulnerability researcher. Details of vsftpd are at http://vsftpd.beasts.org/. His work includes vulnerabilities in all the major browsers (Firefox, Safari, Internet Explorer, Opera, Chrome); the Linux and OpenBSD kernels; Sun's JDK; and lots of open source packages. He blogs about some of his work at [http://scarybeastsecurity.blogspot.com http://scarybeastsecurity.blogspot.com]. At Google, Chris currently leads security for Google Chrome. He has presented at various conferences (PacSec, HiTB Dubai, HiTB Malaysia, BlackHat Europe, HiTB Amsterdam, OWASP, etc.) and is on the HiTB and WOOT paper selection panels. [http://www.linkedin.com/in/scarybeast Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Michael Craigue  ==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;background-color: transparent&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;200&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;1000&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | https://www.owasp.org/images/0/0c/MichaelCraigue.jpg &lt;br /&gt;
| align=&amp;quot;justify&amp;quot; | [http://www.linkedin.com/in/craigue Michael Craigue] (CISSP/CSSLP) is Director of the Security Consulting group at Dell, with 14 team members in Brazil, India, Malaysia, and the US. He and his team have responsibility for consulting with all of Dell’s internal organizations, including IT, Product Group, Services, and Mergers and Acquisitions, with a particular focus on the Secure Software Development Lifecycle. He has taught Database Management and Business Intelligence / Knowledge Management at St. Edward’s University in their MBA / MS CIS programs. Prior to joining Dell’s information security team, he spent a decade building Web and database applications. He has a PhD from the University of Texas at Austin in Higher Education Administration / Finance. [http://www.linkedin.com/in/craigue Linkedin]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 04 à 05 de Outubro (Treinamentos)  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
'''Treinamento 1''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Breno Silva&lt;br /&gt;
&lt;br /&gt;
'''Título''': ModSecurity training&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This is a Hands-On traning about ModSecurity (WAF). People in this class will learn the main topics of ModSecurity, including installation, modes of deployment, configuration, rule customization and logging.&lt;br /&gt;
&lt;br /&gt;
'''1. O que é ModSecurity?'''&lt;br /&gt;
  *     Como instalar&lt;br /&gt;
  *     Arquiteturas&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''2.      Configurando ModSecurity'''&lt;br /&gt;
  *     Principais diretivas de configuração&lt;br /&gt;
  *     Core Rule Set (CRS)&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
&lt;br /&gt;
'''3.      Customizando regras'''&lt;br /&gt;
  *     Sintaxe&lt;br /&gt;
  *     Fases&lt;br /&gt;
  *     Principais variáveis&lt;br /&gt;
  *     Principais operadores&lt;br /&gt;
  *     Principais ações&lt;br /&gt;
  *     Funções de transformação&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
  *     Exercicio 2&lt;br /&gt;
  *     Exercicio 3&lt;br /&gt;
  *     Exercicio 4&lt;br /&gt;
&lt;br /&gt;
'''4.      Logging'''&lt;br /&gt;
  *     Entendendo as Log parts&lt;br /&gt;
  *     Exercicio 1&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Breno is a computer scientist with over 8 years experience in Information Technology, experienced with a wide range of software development techniques and languages, security systems and network      technologies. Breno brings a deep mathematical education, supporting research and algorithm design for network anomaly detection mechanisms in high-speed networks. Breno is currently a security       researcher for TrustWave Spiderlabs team, also the maintainer of ModSecurity, developement team member of Suricata IDS/IPS. He worked as a computer incidente response team member for the              Telecom Industry in Latin America. Breno resides in Brasília, Brazil.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------&lt;br /&gt;
'''Treinamento 2''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Fabio Cerullo&lt;br /&gt;
&lt;br /&gt;
'''Título''': Introduction to Web Application Security&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your Java or .Net applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
?Hands on&lt;br /&gt;
The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Fabio is currently working as an Information Security Specialist at AIB Bank (Dublin, Ireland). His tasks include performing risk analysis, assessing the security of web applications developed internally or purchased from third parties, define policies and standards on secure coding, as well as providing training on web application security to developers, auditors, executives and security professionals. Prior to joining AIB, he worked as a Security Engineer at the European headquarters of Symantec Security Response analyzing malicious code, blended threats, security risks and vulnerabilities in various applications. Before moving to Ireland, he worked in the development of different training programs and activities with emphasis on secure software development in his native Argentina. As a member of the OWASP organization, Fabio is part of Global Education Committee whose mission is to provide training and educational services to businesses, governments and educational institutions on application security; he coordinates international conferences around this topic, and since early 2010 has been appointed chairman of OWASP Chapter in Ireland. Fabio is a graduate in Computer Engineering from the Universidad Católica Argentina and has been granted the CISSP by (ISC) 2 back in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
---------------------------------&lt;br /&gt;
'''Treinamento 3''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Juan Carlos Calderon&lt;br /&gt;
&lt;br /&gt;
'''Título''': Protecting Java Web Applications against known (and unknown) vulnerabilities with the new Mod_Security for Java.&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
Explanation on how Mod_Security for Java works, when is more suitable, how to install it, configure it and create rules in both XML and Mod_Security format to protect a java application against common vulnerabilities in OWASP Top 10 and SANS/CWE 25. Also an introduction to OWASP Mod_Security Core Ruleset to protect application on dangerous patterns that can lead to vulnerabilities not publicly available right now.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professional with 11 years of application security expertise working for multinational companies in the Financial, Aviation, Media and transportation industries, supporter of OWASP as project leader since 5 years ago and CSSLP certified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
'''Treinamento 4''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Magno Rodrigues&lt;br /&gt;
&lt;br /&gt;
'''Título''': OWASP Top 10 + Java EE&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
The goal of this training is to give a better understanding about the top 10 risks that are more critical to web applications using the OWASP Top 10 v.2010 document, that describes them, their impacts and how to avoid them. We will go through all 10 risks, showing what they are with practical examples and detailed explanation. Participants will have the opportunity to practice the search and fixing of theses risks with a vulnerable web application called WebGoat, which is also an OWASP Project developed in Java EE. All the examples will be in Java, so previous knowledge of this programming language is a plus but not mandatory.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o Instrutor''':&lt;br /&gt;
Magno Rodrigues de Oliveira é Líder e Fundador do Capítulo da OWASP na Paraíba. Pós-Graduando em Segurança da Informação pela Faculdade de Tecnologia de João Pessoa. Realizou um curso de 1 (um) ano em Forense Computacional em Nova York, EUA. Formado em Tecnologia em Sistemas para Internet pelo Instituto Federal de Educação, Ciência e Tecnologia da Paraíba. Trabalha atualmente como Analista de Sistemas da Politec, prestando serviços para a Secretaria de Estado da Receita da Paraíba.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-------------------------------------&lt;br /&gt;
'''Treinamento 5''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Alexandre Melo Braga&lt;br /&gt;
&lt;br /&gt;
'''Título''': Introdução à criptografia ilustrada em Java para programadores web&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A criptografia é a única tecnologia capaz de proteger dados em trânsito. O mimicurso terá o seguinte conteúdo geral: criptografia simétrica, criptografia assimétrica, modos de operação de cifras de bloco, funções de hash, funções MAC, geradores números pseudo-aleatórios e protocolos de acordo de chaves e SSL. Uma vez que se trata de um treinamento para programadores, todo o conteúdo será exemplificado em Java e será dada ênfase à identificação de maus usos de criptografia. O minicurso tem o aspecto prático de que todos os programas serão manipulados no treinamento, não apenas e PPT.&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Professor de graduação em tecnologia e segurança por 10 anos&lt;br /&gt;
Professor de pós-graduação em desenvolvimento seguro de software e criptografia há 5 anos.&lt;br /&gt;
Autor de diversos artigos científicos&lt;br /&gt;
Instrutor de diversos treinamentos  para organizações privadas no Brasil e no exterior assim como para instituições educacionais.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------------------------------------&lt;br /&gt;
'''Treinamento 6''':&lt;br /&gt;
&lt;br /&gt;
'''Instrutor''': Tarcizio Vieira Neto&lt;br /&gt;
&lt;br /&gt;
'''Título''': Uso da OWASP ESAPI (Enterprise Security API) para prover segurança em aplicações Web&lt;br /&gt;
&lt;br /&gt;
'''Resumo''':&lt;br /&gt;
A evolução da tecnologia no desenvolvimento de aplicações WEB tem contribuído com o aumento significativo do uso dessa tecnologia para atender os mais diversificados propósitos. Porém, essa tecnologia está sujeita a diversas vulnerabilidades de segurança críticas, principalmente quando pesquisas recentes apontam que a maioria das vulnerabilidades estão presentes na própria aplicação.&lt;br /&gt;
A biblioteca ESAPI (Enterprise Security API), da OWASP, surge neste cenário como uma biblioteca de segurança open source disponível para diversas linguagens, como Java EE, PHP, .NET, ASP Clássico, Python, Ruby, entre outras. O minicurso aborda de modo prático as vulnerabilidades causadas por erros comuns no desenvolvimento de aplicações e os mecanismos de controle de segurança providos pela biblioteca ESAPI com o foco na tecnologia Java. Os princípios gerais aprendidos no curso podem ser aplicados no contexto das demais linguagens de programação.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Sobre o instrutor''':&lt;br /&gt;
Tarcizio Vieira Neto é graduado em Ciência da Computação pela Universidade Federal de Goiás (UFG), em Goiânia. Atualmente trabalha no SERPRO, desde novembro de 2009, como Analista de Desenvolvimento, na Coordenação Estratégica de Tecnologia CETEC, desenvolvendo trabalhos sobre o tema segurança no desenvolvimento de aplicações, envolvendo aspectos processuais e técnicos, como também participa da prospecção de ferramentas que dão suporte à segurança no desenvolvimento de aplicações Web.&lt;br /&gt;
Participou também como instrutor no treinamento de novos empregados e auxiliou na elaboração do material do curso em Ensino a Distância na universidade corporativa do SERPRO (UniSERPRO).&lt;br /&gt;
Participou da primeira versão da tradução do OWASP Secure Coding Principles Quick Reference Guide, para o português brasileiro e liderou o projeto de revisão da tradução do mesmo documento.&lt;br /&gt;
Possui especialização em gestão da segurança da informação pela Universidade de Brasília (UnB).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 06 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== 07 de Outubro  ====&lt;br /&gt;
&lt;br /&gt;
== Agenda  ==&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
==== Inscrições  ====&lt;br /&gt;
&lt;br /&gt;
Será divulgada em breve. &lt;br /&gt;
&lt;br /&gt;
=== Preços ===&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Informações  ====&lt;br /&gt;
&lt;br /&gt;
== Guia Turístico  ==&lt;br /&gt;
&lt;br /&gt;
Portão de entrada de turistas no Estado e a apenas 120 quilômetros da aprazível Serra Gaúcha, Porto Alegre é um movimentado pólo de serviços e de infraestrutura de qualidade reconhecidas, base de grandes empresas nacionais e internacionais e um dos principais destinos de eventos internacionais no Brasil. &lt;br /&gt;
&lt;br /&gt;
Links úteis: [http://www2.portoalegre.rs.gov.br/turismo http://www2.portoalegre.rs.gov.br/turismo] &lt;br /&gt;
&lt;br /&gt;
[https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre https://secure.wikimedia.org/wikipedia/pt/wiki/Porto_Alegre] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt; Recente reportagem do programa americano 60 Minutes sobre o potencial de crescimento do Brasil: &amp;lt;br&amp;gt; &lt;br /&gt;
{{#ev:youtube|DMM7OJ_Kj9I}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Vídeo turístico sobre Porto Alegre:&amp;lt;br&amp;gt;&lt;br /&gt;
{{#ev:youtube|pXQ9z8sPcHI}} &lt;br /&gt;
&lt;br /&gt;
== Tomadas Elétricas  ==&lt;br /&gt;
&lt;br /&gt;
[http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html https://www.owasp.org/images/0/0f/Tomadas_diversas.jpg] &amp;lt;br&amp;gt;&lt;br /&gt;
Referência: [http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html http://omegatek.blogspot.com/2010/05/novo-padrao-de-tomadas-brasileiras.html]&lt;br /&gt;
&lt;br /&gt;
== Previsão do Tempo  ==&lt;br /&gt;
&lt;br /&gt;
== Viagem  ==&lt;br /&gt;
&lt;br /&gt;
== Acomodações  ==&lt;br /&gt;
&lt;br /&gt;
'''NOVOTEL PORTO ALEGRE'''&amp;lt;br&amp;gt;&lt;br /&gt;
Av. Soledade, 575&amp;lt;br&amp;gt;&lt;br /&gt;
Três Figueiras&amp;lt;br&amp;gt;&lt;br /&gt;
Fone: (51) 3327-9292&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Single / Double&amp;lt;br&amp;gt;&lt;br /&gt;
R$243,00 / R$289,00&amp;lt;br&amp;gt;&lt;br /&gt;
Café da manhã cortesia&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
CONDIÇÕES GERAIS&amp;lt;br&amp;gt;&lt;br /&gt;
. Diárias expressas em reais (R$), por dia e por apartamento; . Diárias iniciam e terminam às 12 horas; . Taxa de Turismo (opcional) - R$2,50 por dia/apartamento; . Imposto Municipal: acrescer 5% ISS; . O acesso à internet nas áreas sociais e nos apartamentos é cortesia; . Estacionamento: R$16,00 por carro ao dia (com manobrista); . Terceira pessoa no apartamento: Mediante disponibilidade. Cobrada taxa diária de R$47,00 + 5% ISS e será acomodada em cama extra ou sofá cama; . Forma de Pagamento: Depósito antecipado ou pagamento direto; . Garantia de No Show: Todas as reservas deverão ter garantia de no show. Em caso de não comparecimento, poderá ser cobrado o período integral reservado; . Não aceitamos cheques; . Duas crianças de até 16 anos no Novotel e uma criança de até 12 anos no Mercure acompanhadas dos pais/responsáveis no mesmo apartamento serão cortesia.&lt;br /&gt;
Necessária apresentação de documentação de identificação no check-in; . Valores pagos não serão reembolsáveis ou dados como créditos para próximas hospedagens;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Link do mapa:&amp;lt;br&amp;gt;&lt;br /&gt;
http://maps.google.com.br/maps?hl=pt-BR&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;q=novotel+porto+alegre&amp;amp;fb=1&amp;amp;gl=br&amp;amp;hq=novotel&amp;amp;hnear=0x9519784e88e1007d:0xc7011777424f60bd,Porto+Alegre+-+RS&amp;amp;cid=0,0,11722004907679800889&amp;amp;ei=GKn4TfaHDIP20gGF9pXDCw&amp;amp;sa=X&amp;amp;oi=local_result&amp;amp;ct=image&amp;amp;resnum=1&amp;amp;ved=0CDAQnwIwAA&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/3/33/Novohotel.jpg&lt;br /&gt;
&lt;br /&gt;
==== Eventos Sociais  ====&lt;br /&gt;
&lt;br /&gt;
Serão divulgados em breve. &lt;br /&gt;
&lt;br /&gt;
==== Patrocínios  ====&lt;br /&gt;
&lt;br /&gt;
Estamos atualmente buscado patrocinadores para a edição 2011 da Global AppSec Latin América. Veja mais detalhes sobre as oportunidades de patrocínio. &lt;br /&gt;
&lt;br /&gt;
Se estiver interessado em patrocinar o Global AppSec Latin América 2011, por favor entre em contato com a equipe organizadora da conferência pelo email [mailto:AppSec2011@AppSecLatam.org AppSec2011@AppSecLatam.org]. &lt;br /&gt;
&lt;br /&gt;
Para mais detalhes sobre diferentes oportunidades de patrocínio, por favor verifique o documento abaixo:&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.owasp.org/images/c/cf/OWASP_AppSec_2011_Sponsorship_Portuguese.pdf OWASP AppSec 2011 Sponsorship Portuguese.pdf]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Diamante ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:elipse_logo3.png|link=http://www.elipse.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Platina ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Ouro ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:IT2S.png|link=http://www.it2s.com.br]]  &amp;amp;nbsp;&lt;br /&gt;
[[Image:trustwaveappseclatam.jpg|link=https://www.trustwave.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocínio Prata ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Adobe_logo5.png|link=http://www.adobe.com]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Patrocinadores do kit da conferência  ==&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:LogotipoConvisoCor.png‎|200px|link=http://www.conviso.com.br]] &amp;amp;nbsp; [[Image:LgClavis.jpg‎|link=http://www.clavis.com.br]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Organização Local ==&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
[[Image:Logo-PoaSec2.png|link=http://www.poasec.org]] &lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
==== Organizadores  ====&lt;br /&gt;
&lt;br /&gt;
[mailto:abc@elipse.com.br Alexandre Balestrin Correa]&amp;lt;br&amp;gt; &lt;br /&gt;
[http://cassiogoldschmidt.com/ Cassio Goldschmidt]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Jeronimo_Zucco Jerônimo Zucco ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Gustavo_Barbato L. Gustavo C. Barbato ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Sapao Lucas C. Ferreira ]&amp;lt;br&amp;gt; [http://www.owasp.org/index.php/User:Rafael_Dreher Rafael Dreher ]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Chapter Leader Workshop ====&lt;br /&gt;
&lt;br /&gt;
=='''What is the Chapter Leader Workshop?''' ==&lt;br /&gt;
On '''Wednesday, October 5,2011 at 13:30h-16:30h''' the Global Chapter Committee is organizing a chapter leader workshop for all the chapter leaders that attend the conference. ''Please note that this Workshop will take place on the day before the Conference starts.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Items that will be discussed are:'''&lt;br /&gt;
* How to improve the current Chapter Leader Handbook?&lt;br /&gt;
* How to start and support new chapters within Latin America?&lt;br /&gt;
* How to support inactive chapters within Latin America?&lt;br /&gt;
* What Governance model is required for OWASP chapters?&lt;br /&gt;
* How can the Global Chapters Committee facilitate the Latin American chapters?&lt;br /&gt;
* ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additionally we hope to make time and space available to do hands-on work revising the [[Chapter Leader Handbook]], details TBA.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Funding to Attend the Workshop''' ==&lt;br /&gt;
&lt;br /&gt;
If you need financial assistance to attend the Chapter Leader Workshop at AppSec Latin America, please submit a request to [mailto:tin.zaw@owasp.org Tin Zaw] and [mailto:sarah.baso@owasp.org Sarah Baso] by '''August 22, 2011'''. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Funding for your attendance to the workshop should be worked out in the following order. &lt;br /&gt;
&lt;br /&gt;
# Ask your employer to fund your trip to AppSec Latin America conference.&lt;br /&gt;
# Utilize your chapter funds.&lt;br /&gt;
# Ask the chapter committee for funding assistance. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. After August 22, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''RSVP and Details''' ==&lt;br /&gt;
&lt;br /&gt;
To RSVP and view more details about the Workshop, go to the  '''[[AppSecLatam2011 chapters workshop agenda]]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== '''Contact''' ==&lt;br /&gt;
&lt;br /&gt;
Email [mailto:sarah.baso@owasp.org Sarah Baso] or [mailto:tin.zaw@owasp.org Tin Zaw] for more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Rafael Dreher</name></author>	</entry>

	</feed>