This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP New Zealand Day 2019"

From OWASP
Jump to: navigation, search
(Added Toni James talk)
(Added placeholder for Toni James abstract and speaker bio)
Line 262: Line 262:
 
* Toni James
 
* Toni James
 
* Arshad Khan
 
* Arshad Khan
 +
* Alex McClennan
 
* Stephen Sherry
 
* Stephen Sherry
 
* Anneke Smitheram
 
* Anneke Smitheram
Line 605: Line 606:
 
Louis is a security engineer based in Melbourne, Australia. He performs pentest, architecture and code review. Louis is the founder of PentesterLab, a learning platform for Web penetration testing. Recently, Louis talked at OWASP AppSecDay Melbourne, and ran two workshops at DEF CON 26, in 2018.
 
Louis is a security engineer based in Melbourne, Australia. He performs pentest, architecture and code review. Louis is the founder of PentesterLab, a learning platform for Web penetration testing. Recently, Louis talked at OWASP AppSecDay Melbourne, and ran two workshops at DEF CON 26, in 2018.
  
=== Security Regression Testing on OWASP ZAP Node API ===
+
=== CTF: The Gateway Drug ===
 
----
 
----
=== Kim Carter - BinaryMist ===
+
=== Toni James - Orion Health ===
  
 
====Abstract====
 
====Abstract====
  
The OWASP ZAP HTTP intercepting proxy is useful for manually attacking your Web apps and APIs. Now, we have the official Node API to programatically drive ZAP to regression test our creations. I’ll show you how to build a fully featured security regression testing CLI, consumable by your CI/nightly builds.
+
 
  
 
====Speaker Biography====
 
====Speaker Biography====
  
Kim is a Technologist / Engineer, Information Security Professional, Entrepreneur, and the founder of BinaryMist Ltd. He is one of the OWASP NZ Chapter leaders and a Certified Scrum Master. Facilitator, mentor and motivator of cross functional, self managing teams. With a solid 17 years of commercial industry experience across many domains, Kim enjoys teaching others how to apply information security to their Agile processes, bringing the security focus up front where it’s the cheapest to implement, increasing profit and reducing costs. Co-organiser of the Christchurch Hacker Con, International trainer, speaker, published author, and Software Engineering Radio podcast host, focusing on software and network architecture, Web development and engineering, and information security. Kim is also a regular blog poster. Kim loves designing and creating robust software and networks, breaking software and networks, then fixing them and helping organisations increase productivity.
+
 
  
 
==Track One - Afternoon 1 (13:30 - 15:30) ==
 
==Track One - Afternoon 1 (13:30 - 15:30) ==
Line 669: Line 670:
 
==Track Two - Afternoon 1 (13:30 - 15:30)==
 
==Track Two - Afternoon 1 (13:30 - 15:30)==
  
=== How to Lose a Container in 10 Minutes ===
+
=== Security Regression Testing on OWASP ZAP Node API ===
 
----
 
----
=== Sarah Young - Microsoft ===
+
=== Kim Carter - BinaryMist ===
  
 
====Abstract====
 
====Abstract====
  
Moving to the cloud and deploying containers? In this talk I discuss both the mindset shift and tech challenges, with some common mistakes made in real-life deployments. We’ll also look at what happens to a container that’s been left open to the Internet for the duration of the talk.
+
The OWASP ZAP HTTP intercepting proxy is useful for manually attacking your Web apps and APIs. Now, we have the official Node API to programatically drive ZAP to regression test our creations. I’ll show you how to build a fully featured security regression testing CLI, consumable by your CI/nightly builds.
  
 
====Speaker Biography====
 
====Speaker Biography====
  
Sarah is a security architect based in Melbourne. She has a decade of experience in tech and is particularly interested in cloud security, container security and good ol’ fashioned networking and infrastructure security (having previously worked as a network engineer). In her current role, Sarah helps enterprises move into the cloud securely, design their secure pipeline and adopt automated security processes. Sarah spends most of her spare time speaking at security conferences in various parts of the world, eating hipster brunches and high teas and spending a disproportionate amount of her income on travel. She is still holding out hope that - despite the obvious blockers - either Justin Trudeau or Prince Harry will become her husband one day.
+
Kim is a Technologist / Engineer, Information Security Professional, Entrepreneur, and the founder of BinaryMist Ltd. He is one of the OWASP NZ Chapter leaders and a Certified Scrum Master. Facilitator, mentor and motivator of cross functional, self managing teams. With a solid 17 years of commercial industry experience across many domains, Kim enjoys teaching others how to apply information security to their Agile processes, bringing the security focus up front where it’s the cheapest to implement, increasing profit and reducing costs. Co-organiser of the Christchurch Hacker Con, International trainer, speaker, published author, and Software Engineering Radio podcast host, focusing on software and network architecture, Web development and engineering, and information security. Kim is also a regular blog poster. Kim loves designing and creating robust software and networks, breaking software and networks, then fixing them and helping organisations increase productivity.
  
 
=== CI Can Make $$$ from Thin Air ===
 
=== CI Can Make $$$ from Thin Air ===

Revision as of 21:41, 18 February 2019

NZDay_2019_web_banner.jpg

21st and 22nd February 2019 - Auckland


UPDATE #6 (15 February) - Registration for training classes is now CLOSED.

UPDATE #5 (23 January) - The presentation schedule, talk abstracts, and speaker bios have been posted. Check the "Presentation Schedule" and "Abstracts and Bios" tabs below.

UPDATE #4 (12 January) - The Call for Presentations is now closed. Those submitting proposals will be notified shortly whether their talks have been accepted.

UPDATE #3 (7 January) - Registration for Training Classes Now Open! Visit EventBrite to reserve your spot!

UPDATE #2 (22 December) - Registration Now Open! Visit EventBrite to register now!

IMPORTANT UPDATE (21 December) - Call for Presentations Extended: The Call for Presentations has been extended, and will now close on Friday, 11 January, 2019.

Introduction

We are proud to announce the tenth OWASP New Zealand Day conference, to be held at the University of Auckland on Friday, February 22nd, 2019. OWASP New Zealand Day is a one-day conference dedicated to information security, with an emphasis on secure architecture and development techniques to help Kiwi developers build more secure applications.

There will be two streams throughout the day. The first stream will include introductory talks on application and information security topics, as well as on policy, compliance, and risk management. The second stream will primarily address deeper technical topics.

Who is it for?

  • Web Developers
  • Security Professionals and Enthusiasts
  • Program and Project Managers
  • Business Analysts
  • Requirements Analysts
  • Software Testers

Conference structure

Date: Friday, 22 February 2019

Time: 9:00am - 6:00pm

Cost: FREE

The main conference is on Friday, the 22nd of February, and will have two streams in both the morning and the afternoon:

Stream One:

  • Introductory Topics
  • Program Management, Policy, Compliance, Risk Management

Stream Two:

  • Technical Topics

Training

In addition the main conference on Friday, we are pleased to be offer three training opportunities on Thursday, at the same venue. Course details, including registration, are as follows:

Real-World Penetration Testing

Date: Thursday, 21 February 2019
Time: 8:45 a.m. - 5:30 p.m.
Format: Live online interaction with instructors; interactive Web-based lab exercises
Instructors: Vivek Ramachandran and Nishant Sharma
Instructors' Organisation: Pentester Academy
Registration Fee: $500.00
Training Registration Page (Registration CLOSED)

Are You a Secure Code Warrior?

Date: Thursday, 21 February 2019
Time: 8:45 a.m. - 12:30 p.m.
Instructor: Jaap Karan Singh
Instructor's Organisation: Secure Code Warrior
Registration Fee: $250.00
Training Registration Page (Registration CLOSED)

Threat Modelling: Getting from None to Done

Date: Thursday, 21 February 2019
Time: 8:45 a.m. - 5:30 p.m.
Instructor: Dr. John DiLeo
Instructor's Organisation: OWASP New Zealand Chapter
Registration Fee: $500.00
Training Registration Page (SOLD OUT)

Training registration closed at midnight on 14 February.

General

The tenth OWASP New Zealand Day will be happening thanks to the support provided by the University of Auckland, which will kindly offer the same facilities as those we used in 2018. Entry to the event will, as in the past, be free.

For any comments, feedback or observations, please don't hesitate to contact us.

Registration

Registration is now open. Visit EventBrite to register.

Please join our low volume mailing list to be notified as further schedule information becomes available, and/or follow us on Twitter @owaspnz.

There is no cost for the main conference day. Currently, we are planning to provide morning and afternoon tea; however, this is subject to meeting our sponsorship goals for the event. Spaces are limited, so we do ask that, if at any point you realise you will not be able to attend, you cancel your registration (i.e., "request a refund" in EventBrite) to make room for others.

Important dates

CFP submission deadline: 11th January 2019 - Submissions are now closed
CFT submission deadline: 21st December 2018 - Submissions are now closed
Training Day date: 21st February 2019
Training Registration Deadline: 14th February 2019 - Registration is now closed
Conference Day date: 22nd February 2019
Conference Registration deadline: 22nd February 2019 (Same-day registration is permitted, if space is available)

For those of you booking flights, ensure you can be at the venue by 8:30am. The conference will end by 6:00pm. However, we will have post conference drinks at a local drinking establishment for those interested. We are planning to hold a special event on Thursday evening for speakers, trainers, sponsors, and conference volunteers - more details on that to follow.

Places to eat & drink on the day

The University published a handy map (in 2018), to help you find places to eat around campus: File:Retail Map City Campus 2018 v2.pdf

Some of the options available:

  • The Deli - Located on Level 1 of the Owen G. Glenn Building - This is closest, but will probably have long lines
  • Mojo Symonds - also on campus
  • Shakey Isles - coffee and food across the road on the corner of Symonds & Alfred St
  • The CBD - walk up and over Albert Park to get to the CBD with many great food options
    • Fort Street has burgers, kebabs, and KFC
    • High Street & Lorne Street have lots of little cafes and restaurants
  • Subway, Starbucks, St. Pierre's Sushi & Pita Pit - walk up Symonds Street
  • Vulture’s Lane is a popular pub with the InfoSec crowd, there are more seats downstairs
  • The Bluestone Room - also a popular pub just across Queen St

Conference Venue

The University of Auckland School of Business
Owen G. Glenn Building (OGGB)
Address: 12 Grafton Road

Stream One: Level 1
Room: 115 (Fisher & Paykel Auditorium)

Stream Two: Level 0
Room: 098

Auckland
New Zealand
Map

073 AUBiz 10Apr08small.jpg OWASPNZDayLectureTheatre.jpg

Conference Sponsors

For more information on our Premier Sponsors, please visit our About Our Sponsors page

Conference Host

AuckUni.png

Platinum Sponsor

 
Logo-Insomnia Security
 

Gold Sponsors

Logo-Orion Health
Logo-Quantum Security
Logo-Secure Code Warrior
Logo-ZX Security
 

Silver Sponsors

Sponsoring Provider - Training Day Tea Breaks

Logo-Aura Information Security

Supporting Sponsors

     Logo-Binary Mist Limited
     Logo-PentesterLab
      Logo-Privasec
     Logo-RedShield

Logo-Zimbra


Follow us on Twitter (@owaspnz)

OWASP New Zealand on Facebook