<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=1st_OWASP_IL_mini_conference</id>
		<title>1st OWASP IL mini conference - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=1st_OWASP_IL_mini_conference"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;action=history"/>
		<updated>2026-04-12T09:06:14Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;diff=49019&amp;oldid=prev</id>
		<title>Oshezaf at 15:21, 15 December 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;diff=49019&amp;oldid=prev"/>
				<updated>2008-12-15T15:21:43Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 15:21, 15 December 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Israel]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006 ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006 ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Oshezaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;diff=23795&amp;oldid=prev</id>
		<title>Oshezaf: /* Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006 */</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;diff=23795&amp;oldid=prev"/>
				<updated>2007-12-02T12:20:29Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 12:20, 2 December 2007&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot; &gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The meeting was sponsored by [[www.breach.com|Breach Security]] and [[www.applicure.com|Applicure Technologies]].&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The meeting was sponsored by [[www.breach.com|Breach Security]] and [[www.applicure.com|Applicure Technologies]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Breach_logo.gif]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;[[Image&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Applicure_logo&lt;/del&gt;.JPG&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;|180px]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Breach_logo.gif]] &amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;amp;nbsp; https&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;//www.owasp.org/images/c/c8/OWAS_IL_Sponsor_Applicure&lt;/ins&gt;.JPG &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Use the links in the event program to access the presentations themselves:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Use the links in the event program to access the presentations themselves:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Oshezaf</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;diff=20927&amp;oldid=prev</id>
		<title>Oshezaf: New page: == Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006 ==  OWASP IL and the Interdisciplinary Center Herzliya (IDC) held a half day conference on applic...</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_OWASP_IL_mini_conference&amp;diff=20927&amp;oldid=prev"/>
				<updated>2007-08-20T06:34:42Z</updated>
		
		<summary type="html">&lt;p&gt;New page: == Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006 ==  OWASP IL and the Interdisciplinary Center Herzliya (IDC) held a half day conference on applic...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Held at the Interdisciplinary Center (IDC) Herzliya, May 21th 2007 , November 13th 2006 ==&lt;br /&gt;
&lt;br /&gt;
OWASP IL and the Interdisciplinary Center Herzliya (IDC) held a half day conference on application security on Nov 13th 2006. The event marked the establishment of a new academic program on information security in the net era at IDC's Efi Arazi School of Computer Science. More than 90! people attended the conference, enjoyed professional catering and heard no less than 7 presentations.&lt;br /&gt;
&lt;br /&gt;
The meeting was sponsored by [[www.breach.com|Breach Security]] and [[www.applicure.com|Applicure Technologies]].&lt;br /&gt;
&lt;br /&gt;
[[Image:Breach_logo.gif]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[Image:Applicure_logo.JPG|180px]]&lt;br /&gt;
&lt;br /&gt;
Use the links in the event program to access the presentations themselves:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''15:00 – 15:10 Introducing the new information security program at the net era at the Efi Arazi School of Computer Science, IDC Herzliya'''&amp;lt;/big&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Dr. Anat Bremler-Barr, Program Academic Director.[[Image:OWASP_IL_IDC.jpg|right]]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;big&amp;gt;'''15:10 – 15:40 Sophisticated Denial of Service attacks'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Dr. Anat Bremler-Barr,  Efi Arazi School of Computer Science, IDC Herzliya&lt;br /&gt;
&lt;br /&gt;
In Denial of Service attack, the attackers consume the resources of the victim, a server or a network, causing degradation in performance or even total failure of the victim. The basic DDoS attack is a simple brute force flooding, where the attacker sends as much traffic as he can to consume the network resources. In contrast, the sophisticated DDoS attack aims to hurt the weakest point in the victim's applications by sending specific traffic type that burdens the application the most. In this talk we will cover recent works that show that several common mechanisms are vulnerable to sophisticated DDoS attacks. For example, Crosby and Wallach showed that using bandwidth of less than a typical dialup modem can bring a dedicated Bro server to its knees. We will discuss some basic guidelines of how to design applications to be resilient to sophisticated attacks.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;big&amp;gt;'''15:40 – 16:00 [[Media:Enterprise_portals_security.pdf|Malicious content in enterprise portals]]'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Shalom Carmel, A security icon, the world's authority on hacking AS/400 and a BlackHat 2006 speaker&lt;br /&gt;
&lt;br /&gt;
In 2005, enterprise portals rank in the top 10 of CIO technology focus areas in many surveys. The main drivers of the portal business growth are the horizontal portal suites, which provide content management capabilities, application integration tools, and specific solutions for collaboration and knowledge management. This lecture will address the security problems an enterprise may have due to the various content management abilities in a typical Portal implementation, and will focus on cross site scripting attacks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''16:00 – 16:30 Information Warfare against commercial companies – lessons from dealing with hostile internet entities'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ariel Pisetsky, CISO and Infrastructure Manager, NetVision&lt;br /&gt;
&lt;br /&gt;
During the recent war in the north, many information security events where detected in private and government organization. These events, usually no more than web site defacement, provide an opportunity to examine a large scale hostile activity against web sites affiliated with Israel. Commercial companies with no direct relation to the war found themselves under a direct attack or indirectly affected due to attacks on ISPs and the Internet Infrastructure in Israel. &lt;br /&gt;
&lt;br /&gt;
In the presentation we will discuss what happened during this summer of war, whether it can be classified as information warfare and what are the lessons that can be learnt going forward&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''16:30 – 16:45 Break, coffee, tea &amp;amp; fruits'''&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;big&amp;gt;'''16:45 – 17:15 [[Media:Secure_coding.pdf|Real vs. Virtual Patching]]'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ravid Lazinski, Technical Manager, Applicure Technologies&lt;br /&gt;
&lt;br /&gt;
The penetration team has found a bug. What's next? In order to prevent exploitation, the application has to be patched.&lt;br /&gt;
&lt;br /&gt;
The presentation will discuss the advantage and disadvantages of the two available solutions: patching the application or using an external patching solution in a process called &amp;quot;virtual patching&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;big&amp;gt;'''17:15 – 17:45 [[Media:The_Core_Rule_Set.pdf|&amp;quot;The Core Rule Set&amp;quot;: Generic detection of application layer attacks]]'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Ofer Shezaf, CTO, Breach Security, OWASP IL chapter Leader, Director, the Web Application Security Consortium&lt;br /&gt;
&lt;br /&gt;
Web Applications are unique, each one having its own vulnerabilities and therefore a positive security model is usually considered the optimal way to protect them. The [http://www.modsecurity.org ModSecurity] open source project has recently released a &amp;quot;core rule set&amp;quot;, essentially a set of super signatures that try to provide significant security to custom application without the effort of defining a positive security model.&lt;br /&gt;
&lt;br /&gt;
The lecture will discuss generic application security signatures and rules, how they differ from network centric signatures and their strengths and limitations when dealing with the OWASP top 10 attacks.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
'''17:50 – 18:00 Break'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''18:00 – 18:30 [[Media:OWASP_10_Most_Common_Backdoors.pdf|The OWASP Top Ten Backdoors]]'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yaniv Simsolo, Application Security Consultant, Comsec Consulting&lt;br /&gt;
&lt;br /&gt;
Just as the OWASP Top Ten outlines the top ten mistakes that developers make in applications, the top ten backdoors discuss the features developed on purpose, that do just the same: leave the application vulnerable. Backdoors are more common than developers and system professionals think. Hackers and malicious users can exploit backdoors easily, without leaving any special traces in the system. An SQL interface to an application, providing a lot of flexibility but little security is a good example of such a backdoor.&lt;br /&gt;
&lt;br /&gt;
The presentation will discuss common backdoors found in web applications and how they relate to the OWASP top 10.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;'''18:30 – 19:15 [[Media:Hacking_The_FrameWork.ppt|Hacking The Framework]]'''&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Nimrod Luria, Head Of Consulting Services, 2Bsecure&lt;br /&gt;
&lt;br /&gt;
Modern development environment such as .Net and J2EE promise enhanced security by relying on the framework services rather than good coding. The presentation will demonstrate using real hacking demos the weak points in such frameworks using .Net as an example.&lt;/div&gt;</summary>
		<author><name>Oshezaf</name></author>	</entry>

	</feed>