This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Bucharest AppSec Conference 2017 Training2"
Oana Cornea (talk | contribs) |
Oana Cornea (talk | contribs) |
||
| Line 6: | Line 6: | ||
| style="width:25%" valign="middle" height="30" bgcolor="#CCCCEE" align="center" colspan="0" | '''Trainers''' | | style="width:25%" valign="middle" height="30" bgcolor="#CCCCEE" align="center" colspan="0" | '''Trainers''' | ||
| style="width:40%" valign="middle" height="30" bgcolor="#CCCCEE" align="center" colspan="0" | '''Description''' | | style="width:40%" valign="middle" height="30" bgcolor="#CCCCEE" align="center" colspan="0" | '''Description''' | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
|- | |- | ||
| style="width:10%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | 2 days training <br> 11th and 12th of October <br> daily: 9:00 - 17:00<br><br> | | style="width:10%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | 2 days training <br> 11th and 12th of October <br> daily: 9:00 - 17:00<br><br> | ||
| Line 85: | Line 55: | ||
'''Seats available:''' 20 (first-come, first served)<br> | '''Seats available:''' 20 (first-come, first served)<br> | ||
'''Price: 1000 euros/person'''<br> | '''Price: 1000 euros/person'''<br> | ||
| + | [https://www.eventbrite.com/e/owasp-bucharest-appsec-conference-2017-tickets-35356670754 Register here] | ||
| + | |- | ||
| + | | style="width:10%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | 2 days training <br> 11th and 12th of October <br> daily: 9:00 - 17:00<br><br> | ||
| + | | style="width:25%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | Assessing and securing applications using the OWASP ASVS (Application Security Verification Standard)<br> | ||
| + | |||
| + | | style="width:25%" valign="middle" height="30" bgcolor="#CCEEEE" align="center" colspan="0" | Oana Cornea | ||
| + | | style="width:40%" valign="middle" height="30" bgcolor="#CCEEEE" align="justify" colspan="0" | '''Description:'''<br> | ||
| + | The focus of this training will be on how to build secure applications and how to evaluate them using real world scenarios. The attendees will learn the concepts solving exercises and using various OWASP resources like the OWASP ASVS (Application Security Verification Standard) and the OWASP Testing Guide. | ||
| + | Topics covered:<br> | ||
| + | Day 1: | ||
| + | *Architecture design and threat modelling | ||
| + | *Authentication Flaws | ||
| + | *Session Management Flaws | ||
| + | *Access Control Verification Requirements | ||
| + | *Input Handling and Output Encoding/Escaping | ||
| + | Day 2: | ||
| + | *Cryptography at Rest | ||
| + | *Error Handling and Logging | ||
| + | *Data Protection Verification | ||
| + | *Communications Security | ||
| + | *Business Logic Verification Requirements | ||
| + | *Files and Resources | ||
| + | *Mobile Security | ||
| + | *Web Service Security | ||
| + | <br> | ||
| + | '''Intended audience:''' This training is suitable for developers, quality assurance, code reviewers and penetration testers<br> | ||
| + | '''Skill level: ''' Beginner - intermediate <br> | ||
| + | '''Requirements: Basic web knowledge; laptop with at least 4GB RAM and virtualization software (VMware Workstation Player).''' | ||
| + | <br> | ||
| + | '''Seats available: '''20 (first-come, first served)<br> | ||
| + | '''Price: 400 euros/person'''<br> | ||
[https://www.eventbrite.com/e/owasp-bucharest-appsec-conference-2017-tickets-35356670754 Register here] | [https://www.eventbrite.com/e/owasp-bucharest-appsec-conference-2017-tickets-35356670754 Register here] | ||
|} | |} | ||
Revision as of 20:12, 27 September 2017
Training | |||||
| Time | Title | Trainers | Description | ||
| 2 days training 11th and 12th of October daily: 9:00 - 17:00 |
Advanced Malware Analysis |
Himanshu Khokhar | Description: Advanced Malware Analysis is a fast paced, full hands-on course which starts from the very basics of malware analysis and reverse engineering and then moves to advanced analysis of malwares (including malicious exe, js, pdf and word files as well) which then advances to analyze shellcodes, rootkits and ransomwares. Students taking this course will learn the tools and techniques to understand, analyze and defend against modern day malwares. Syllabus 1. Malware ananlysis fundamentals
2. Advanced Static Analysis
3. Advanced Dynamic malware analysis
4. Other major types of malware types
5. Shellcodes, Rootkits and Ransomwares
Intended audience:Advanced Malware Analysis is a full hands-on course. It is useful both for beginners into the field of malware analysis, as well as for those who have been into this area for some time but want to polish their skills to a new level. Other than malware analysts, reverse engineers, forensic investigators, threat analysts, students, people wanting to get into malware analysis can take this course. | ||
| 2 days training 11th and 12th of October daily: 9:00 - 17:00 |
Assessing and securing applications using the OWASP ASVS (Application Security Verification Standard) |
Oana Cornea | Description: The focus of this training will be on how to build secure applications and how to evaluate them using real world scenarios. The attendees will learn the concepts solving exercises and using various OWASP resources like the OWASP ASVS (Application Security Verification Standard) and the OWASP Testing Guide.
Topics covered:
Day 2:
| ||