This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP BeNeLux-Days 2018"

From OWASP
Jump to: navigation, search
(Talks)
 
(39 intermediate revisions by 6 users not shown)
Line 6: Line 6:
 
<!-- First tab -->
 
<!-- First tab -->
 
= Information  =
 
= Information  =
<!--
 
== Keynote Speaker ==
 
  
{{#switchtablink:Conference Day|<p>
+
<p style="text-align:center">'''Thanks to all speakers and trainers, sponsors and volunteers who could make this 2018 edition a success.<br>'''</p>
*  TBD
+
 
}}
+
Sad you missed the conference? No problem, just have a look at the {{#switchtablink:Conference_Day|video recordings}}!
-->
+
 
 +
 
 +
== Save the date ==
 +
 
 +
<p style="text-align:center"><font color="red">'''In 2019 we will skip one year (we organised Global AppSec Amsterdam), See you next year in the Netherlands: 26 and 27 November 2020'''</font></p>
 +
 
 
== Confirmed Conference Speakers ==
 
== Confirmed Conference Speakers ==
  
Line 43: Line 46:
  
 
== OWASP BeNeLux conference is free, but registration is required! ==
 
== OWASP BeNeLux conference is free, but registration is required! ==
 
+
The conference is closed.<br>
[[image:Register_now_red.png|link=https://owasp-benelux-day-2018.eventbrite.com |alt=Register NOW! | Register NOW! ]]
 
  
 
'''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.'''
 
'''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.'''
Line 52: Line 54:
  
 
* Sebastien Deleersnyder / Lieven Desmet / David Mathy / Thomas Herlea / Stella Dineva / Adolfo Solero / Bart De Win, [[Belgium|OWASP Belgium]]
 
* Sebastien Deleersnyder / Lieven Desmet / David Mathy / Thomas Herlea / Stella Dineva / Adolfo Solero / Bart De Win, [[Belgium|OWASP Belgium]]
* Martin Knobloch / Joren Poll / Edwin Goweling, [[Netherlands|OWASP Netherlands]]
+
* Martin Knobloch / Joren Poll / Edwin Gozeling, [[Netherlands|OWASP Netherlands]]
 
* [[Luxembourg|OWASP Luxembourg]]
 
* [[Luxembourg|OWASP Luxembourg]]
  
Line 66: Line 68:
 
= Registration =
 
= Registration =
  
== OWASP BeNeLux conference and training days are free, but registration is required! ==
+
== Registration is closed ==
 
 
[[image:Register_now_red.png|link=https://owasp-benelux-day-2018.eventbrite.com |alt=Register NOW! | Register NOW! ]]
 
 
 
  
 
'''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.'''  
 
'''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.'''  
Line 79: Line 78:
 
== Address ==
 
== Address ==
  
Venue:
+
<table width="100%">
 +
<tr valign="top">
 +
<td width="50%">
 +
=== Training venue ===
 +
 
 +
'''Novotel Mechelen Centrum'''
 +
Van Beethovenstraat 1
 +
2800 Mechelen
 +
Belgium
 +
 
 +
[https://goo.gl/maps/WxErtbWADqC2 Google maps]
 +
</td>
 +
<td width="50%">
 +
=== Conference venue ===
  
 
  '''Congres- en Erfgoedcentrum Lamot'''
 
  '''Congres- en Erfgoedcentrum Lamot'''
Line 87: Line 99:
  
 
[https://goo.gl/maps/gZ9icR178w52 Google map]
 
[https://goo.gl/maps/gZ9icR178w52 Google map]
 +
 +
</td>
 +
</tr>
 +
</table>
 
<br />
 
<br />
 
[[File:Mechelen-Lamot.jpg|350px|Lamot conference center]]
 
[[File:Mechelen-Lamot.jpg|350px|Lamot conference center]]
 
[[File:Mechelen-lamot-center-auditorium.jpg|350px|Auditorium]]<br />
 
[[File:Mechelen-lamot-center-auditorium.jpg|350px|Auditorium]]<br />
 +
 +
  
 
Parking:<br />
 
Parking:<br />
Line 118: Line 136:
  
 
<!-- Fourth tab -->
 
<!-- Fourth tab -->
 +
 
= Training Day =
 
= Training Day =
  
 
'''Training Day is November 29th'''
 
'''Training Day is November 29th'''
 +
 +
== Training Venue ==
 +
 +
The trainings will take place in the '''Novotel Mechelen Centrum''' hotel:<br>
 +
Van Beethovenstraat 1<br>
 +
2800 Mechelen<br>
 +
[https://goo.gl/maps/WxErtbWADqC2 Google maps]
 +
 
== Agenda==
 
== Agenda==
  
 
{| class="wikitable"
 
{| class="wikitable"
 
! Time !! Description !! Training 1 !! Training 2 !! Training 3
 
! Time !! Description !! Training 1 !! Training 2 !! Training 3
 +
|-
 +
! !!  !! (Hof van Busleyden 1) !! (Hof van Busleyden 2) !! (Hof van Kamerijk)
 
|-
 
|-
 
| 08h30 - 9h30
 
| 08h30 - 9h30
| colspan="5" style="text-align: center; background: grey; color: white;" | ''Registration''
+
| style="text-align: center; background: grey; color: white;" colspan="5" | ''Registration''
 
|-
 
|-
 
| 09h30 - 11h00 || Training
 
| 09h30 - 11h00 || Training
| rowspan="7" style="width:100px;" | [[#TRAINING_1 | Kubernetes security]] by Andrew Martin
+
| style="width:100px;" rowspan="7" | [[#TRAINING_1 | Kubernetes security]] by Andrew Martin
| rowspan="7" style="width:100px;" | [[#TRAINING_2 | OWASP Zap Training]] by David Scrobonia
+
| style="width:100px;" rowspan="7" | [[#TRAINING_2 | OWASP Zap Training]] by David Scrobonia
| rowspan="7" style="width:100px;" | [[#TRAINING_3 | Android security workshop]] by Jeroen Beckers & Stephanie Vanroelen
+
| style="width:100px;" rowspan="7" | [[#TRAINING_3 | Android security workshop]] by Jeroen Beckers & Stephanie Vanroelen
 
|-
 
|-
 
| 11h00 - 11h30 ||  ''Coffee Break''
 
| 11h00 - 11h30 ||  ''Coffee Break''
Line 169: Line 198:
 
===== Who Should Attend =====
 
===== Who Should Attend =====
 
This course is suitable for intermediate to advanced Kubernetes users who want to strengthen their security understanding. It is particularly beneficial for those operating Kubernetes in a high-compliance domain, or for established security professionals looking to update their skills for the cloud native world.
 
This course is suitable for intermediate to advanced Kubernetes users who want to strengthen their security understanding. It is particularly beneficial for those operating Kubernetes in a high-compliance domain, or for established security professionals looking to update their skills for the cloud native world.
 +
 +
===== Participant requirements =====
 +
Just a laptop with an SSH client please, ssh or PuTTY.
  
 
==== Bio ====
 
==== Bio ====
Line 190: Line 222:
 
# Using ZAP within your CI/CD Pipeline
 
# Using ZAP within your CI/CD Pipeline
 
   
 
   
 +
===== Participant requirements =====
 +
Please come prepared with the following tools installed:
 +
* ZAP (https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-270-standard)
 +
* docker
 +
 +
If you have any trouble with the setup please feel free to reach out to davidscrobonia at gmail with questions.
 +
 
==== Bio ====
 
==== Bio ====
  
Line 227: Line 266:
  
 
<!-- Fifth tab -->
 
<!-- Fifth tab -->
 
 
= Conference Day =
 
= Conference Day =
  
Line 238: Line 276:
 
! width="190pt" | Speaker  
 
! width="190pt" | Speaker  
 
! width="400pt" | Topic
 
! width="400pt" | Topic
<!-- ! width="100pt" -- ! | Media -->
+
! width="100pt" | Media
 
|-  
 
|-  
 
| 08h30 - 09h15
 
| 08h30 - 09h15
| colspan="3" style="text-align: center; background: grey; color: white" | ''Registration / CyberWayFinder''
+
| style="text-align: center; background: grey; color: white" colspan="3" | ''Registration / [[#CyberWayFinder | Women in cybersecurity (CyberWayFinder)]]''
 
|-  
 
|-  
 
| 09h15 - 09h30
 
| 09h15 - 09h30
| colspan="3" style="text-align: center; background: grey; color: white" | ''Opening''
+
| style="text-align: center; background: grey; color: white" colspan="3" | ''Opening''
 
|-  
 
|-  
 
| 09h30 - 10h15
 
| 09h30 - 10h15
 
| [[#TALK_0930 | Lennert Wouters]]
 
| [[#TALK_0930 | Lennert Wouters]]
 
| [[#TALK_0930 | Fast, Furious and Insecure: Passive Keyless Entry and Start in Modern Supercars]]
 
| [[#TALK_0930 | Fast, Furious and Insecure: Passive Keyless Entry and Start in Modern Supercars]]
<!--| [[Media:TALK_0915_SLIDES|Slides]] [TALK_0915_VIDEO Video]-->
+
|
 
|-
 
|-
 
| 10h15 - 11h00
 
| 10h15 - 11h00
 
| [[#TALK_1015 | Ralph Moonen]]
 
| [[#TALK_1015 | Ralph Moonen]]
 
| [[#TALK_1015 | Weaknesses in our voice communications network: from Blue Boxing to VoLTE]]
 
| [[#TALK_1015 | Weaknesses in our voice communications network: from Blue Boxing to VoLTE]]
<!--| [[Media:TALK_1000_SLIDES|Slides]] [TALK_1000_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 Ralph Moonen - Weaknesses in our voice communications network - from Blue Boxing to VoLTE compressed.pdf | Slides]]<br>
 +
[https://youtu.be/Rl7VabjEd_A Video]
 
|-
 
|-
 
| 11h00 - 11h30  
 
| 11h00 - 11h30  
| colspan="3" style="text-align: center;background: grey; color: white" | ''Morning Break''  
+
| style="text-align: center;background: grey; color: white" colspan="3" | ''Morning Break''  
 
|-
 
|-
 
| 11h30 - 12h15
 
| 11h30 - 12h15
 
| [[#TALK_1130 | Niels Tanis]]
 
| [[#TALK_1130 | Niels Tanis]]
 
| [[#TALK_1130 | When Serverless Met Security… Serverless Security & Functions-as-a-Service (FaaS)]]
 
| [[#TALK_1130 | When Serverless Met Security… Serverless Security & Functions-as-a-Service (FaaS)]]
<!--| [[Media:TALK_1115_SLIDES|Slides]] [TALK_1115_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 Niels Tanis - When Serverless Met Security.pdf | Slides]] <br>
 +
[https://youtu.be/wuvGmXN0n6Q Video]
 
|-
 
|-
 
| 12h15 - 13h00
 
| 12h15 - 13h00
 
| [[#TALK_1215 | David Scrobonia]]
 
| [[#TALK_1215 | David Scrobonia]]
 
| [[#TALK_1215 | OWASP Zap]]
 
| [[#TALK_1215 | OWASP Zap]]
<!--| [[Media:TALK_1200_SLIDES|Slides]] [TALK_1200_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 David Scrobonia OWASP Zap.pdf | Slides]]<br>
 +
[https://youtu.be/iaZaPuQ6ams Video]
 
|-
 
|-
 
| 13h00 - 14h00
 
| 13h00 - 14h00
| colspan="3" style="text-align: center;background: grey; color: white" | ''Lunch''  
+
| style="text-align: center;background: grey; color: white" colspan="3" | ''Lunch''  
 
|-
 
|-
 
| 14h00 - 14h45
 
| 14h00 - 14h45
 
| [[#TALK_1400 | Björn Kimminich]]
 
| [[#TALK_1400 | Björn Kimminich]]
 
| [[#TALK_1400 | Juice Shop: OWASP's most broken Flagship]]
 
| [[#TALK_1400 | Juice Shop: OWASP's most broken Flagship]]
<!--| [[Media:TALK_1345_SLIDES|Slides]] [TALK_1345_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 Bjoern Kimminich - Juice Shop - OWASP's most broken Flagship.pdf | Slides]]<br>
 +
[https://youtu.be/Lu0-kDdtVf4 Video]
 
|-
 
|-
 
| 14h45 - 15h30
 
| 14h45 - 15h30
 
| [[#TALK_1445 | Jo Van Bulck]]
 
| [[#TALK_1445 | Jo Van Bulck]]
 
| [[#TALK_1445 | Leaky Processors: Stealing Your Secrets with Foreshadow]]
 
| [[#TALK_1445 | Leaky Processors: Stealing Your Secrets with Foreshadow]]
<!--| [[Media:TALK_1430_SLIDES|Slides]] [TALK_1430_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 Jo Van Bulck - Leaky Processors - Stealing Your Secrets with Foreshadow.pdf | Slides]] <br>
 +
[https://youtu.be/le60NzmxU6s Video]
 
|-
 
|-
 
| 15h30 - 16h00
 
| 15h30 - 16h00
| colspan="3" style="text-align: center;background: grey; color: white" | ''Afternoon Break''  
+
| style="text-align: center;background: grey; color: white" colspan="3" | ''Afternoon Break''  
 
|-
 
|-
 
| 16h00 - 16h45
 
| 16h00 - 16h45
 
| [[#TALK_1600 | Jeroen Willemsen]]
 
| [[#TALK_1600 | Jeroen Willemsen]]
 
| [[#TALK_1600 | Fast forwarding Mobile Security with the MSTG]]
 
| [[#TALK_1600 | Fast forwarding Mobile Security with the MSTG]]
<!--| [[Media:TALK_1545_SLIDES|Slides]] [TALK_1545_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 Jeroen Willemsen - Fast forwarding Mobile Security with the MSTG compressed.pdf | Slides ]]<br>
 +
[https://youtu.be/WI2_cP48TnA Video]
 
|-
 
|-
 
| 16h45 - 17h30
 
| 16h45 - 17h30
 
| [[#TALK_1645 | Nick Drage]]
 
| [[#TALK_1645 | Nick Drage]]
 
| [[#TALK_1645 | Lessons from the legion (The OWASP BeNeLux Remix)]]
 
| [[#TALK_1645 | Lessons from the legion (The OWASP BeNeLux Remix)]]
<!--| [[Media:TALK_1630_SLIDES|Slides]] [TALK_1630_VIDEO Video]-->
+
| [[Media:OWASP BeNeLux 2018 Nick Drage - Lessons from the Legion compressed.pdf | Slides]]<br>
 +
[https://youtu.be/516Z420BgkE Video]
 
|-
 
|-
 
| 17h30 - 17h45
 
| 17h30 - 17h45
| colspan="3" style="text-align: center;background: grey; color: white" | ''Closing''  
+
| style="text-align: center;background: grey; color: white" colspan="3" | ''Closing''  
 
|}
 
|}
  
Line 399: Line 444:
 
==== Abstract ====
 
==== Abstract ====
  
After the startup of the mobile security project in 2010, the mobile security project and its testing guides have seen quiet some evolution. All of this changed quiet intensively when, in 2016, the Mobile Application Security Verification Standard (MASVS) and the Mobile Application Security Testing Guide (MSTG) were created. Now, two years fast forward: where are we now? How can you use it as a pentester or a developer? We will start with introducing the current state of the MSTG and its side-projects and then show various demos on iOS and Android.<br>
+
After the startup of the mobile security project in 2010, the mobile security project and its testing guides have seen quiet some evolution. All of this changed quiet intensively when, in 2016, the Mobile Application Security Verification Standard (MASVS) and the Mobile Application Security Testing Guide (MSTG) were created. Now, two years fast forward: where are we now? How can you use it as a pentester or a developer? We will start with introducing the current state of the MSTG and its side-projects and then show various demos on iOS.<br>
  
 
==== Bio ====
 
==== Bio ====
  
Jeroen Willemsen is a Principal Security Architect at Xebia. With a love for mobile security, he recently became one of the projectleaders for the OMTG project (MASV & MSTG). Jeroen is more or less a jack of all trades with interest in infrastructure security, risk management and application security.
+
Jeroen Willemsen is a Principal Security Architect at Xebia. With a love for mobile security, he recently became one of the projectleaders for the OMTG project (MASVS & MSTG). Jeroen is more or less a jack of all trades with interest in infrastructure security, risk management and application security.
  
 
=== <span id="TALK_1645">Lessons From The Legion (The OWASP BeNeLux Remix) by Nick Drage</span> ===
 
=== <span id="TALK_1645">Lessons From The Legion (The OWASP BeNeLux Remix) by Nick Drage</span> ===
Line 420: Line 465:
 
Nick is the Director of Path Dependence Limited, and has over two decades of experience in the cyber security field… previously he was "SecOps” before the term was invented, as well as having been a SysAdmin, PCI QSA, pre-sales analyst, CHECK Team Leader, and various other less well defined roles. Nick is currently a Cyber Security Consultant and Penetration Tester, with occasional forays into being a Wargame Umpire, Adversarial Analyst, or Professional Wildcard.
 
Nick is the Director of Path Dependence Limited, and has over two decades of experience in the cyber security field… previously he was "SecOps” before the term was invented, as well as having been a SysAdmin, PCI QSA, pre-sales analyst, CHECK Team Leader, and various other less well defined roles. Nick is currently a Cyber Security Consultant and Penetration Tester, with occasional forays into being a Wargame Umpire, Adversarial Analyst, or Professional Wildcard.
  
=== <span id="CyberWayFinder">Woman in cybersecurity (CyberWayFinder)</span> ===
+
=== <span id="CyberWayFinder">Women in cybersecurity (CyberWayFinder)</span> ===
 
OWASP BeNeLux and CyberWayFinder would like to invite you to a '''breakfast with other women in cybersecurity'''.<br>
 
OWASP BeNeLux and CyberWayFinder would like to invite you to a '''breakfast with other women in cybersecurity'''.<br>
 
Since women make up 7% of the cybersecurity work force, they are a rare breed, and don't often meet each other. That is why "women in cybersecurity breakfasts" are popping up in conferences around the world.
 
Since women make up 7% of the cybersecurity work force, they are a rare breed, and don't often meet each other. That is why "women in cybersecurity breakfasts" are popping up in conferences around the world.
Line 440: Line 485:
  
 
'''Any participant pays individually. <br>Reservation via the form you'll receive after conference registration is mandatory.'''<br>
 
'''Any participant pays individually. <br>Reservation via the form you'll receive after conference registration is mandatory.'''<br>
 
'''If you want to join the social event, don't forget to register for it via the registration:'''
 
[[image:Register_now_red.png|link=https://owasp-benelux-day-2018.eventbrite.com |200px|alt=Register for the OWASP BeNeLux Day 2018 | Register for the OWASP BeNeLux Day 2018 ]]
 
  
  
Line 471: Line 513:
  
 
[[File:DavinsiLabs.png|250px|link=https://www.davinsilabs.com]]
 
[[File:DavinsiLabs.png|250px|link=https://www.davinsilabs.com]]
[http://www.vest.nl https://www.owasp.org/images/6/67/Vest.jpg]
+
[[File:Vest.jpg|250px|link=http://www.vest.nl]]
  
  
Line 480: Line 522:
 
[[File:LogoSynopsys.png|250px|link=https://www.synopsys.com]]
 
[[File:LogoSynopsys.png|250px|link=https://www.synopsys.com]]
 
[[File:Nviso_logo_RGB_baseline_200px.png|250px|link=http://www.nviso.be]]  
 
[[File:Nviso_logo_RGB_baseline_200px.png|250px|link=http://www.nviso.be]]  
 
  
  
Line 486: Line 527:
 
==== Bronze ====
 
==== Bronze ====
  
[https://informatiebeveiliging.nl/ https://www.owasp.org/images/9/9a/Logo_Informatiebeveiliging-200.png]
+
[[File:Logo_Informatiebeveiliging-200.png|250px|link=https://informatiebeveiliging.nl/]]
 
 
  
 
[[Category:OWASP_AppSec_Conference]]  
 
[[Category:OWASP_AppSec_Conference]]  
 
[[Category:OWASP_BeNeLux_Archives]]
 
[[Category:OWASP_BeNeLux_Archives]]

Latest revision as of 13:42, 31 October 2019

OBNL18 Banner v2.png



Thanks to all speakers and trainers, sponsors and volunteers who could make this 2018 edition a success.

Sad you missed the conference? No problem, just have a look at the video recordings!


Save the date

In 2019 we will skip one year (we organised Global AppSec Amsterdam), See you next year in the Netherlands: 26 and 27 November 2020

Confirmed Conference Speakers

  • David Scrobonia
  • Niels Tanis
  • Jeroen Willemsen
  • Björn Kimminich
  • Ralph Moonen
  • Jo Van Bulck
  • Lennert Wouters
  • Nick Drage

Confirmed Trainers

  • Andrew Martin
  • David Scrobonia
  • Jeroen Beckers - Stephanie Vanroelen


OWASP BeNeLux conference is free, but registration is required!

The conference is closed.

To support the OWASP organisation, consider to become a member, it's only US$50! Check out the Membership page to find out more.

The OWASP BeNeLux Program Committee

Tweet!

Event tag is #owaspbnl18

Donate

Made possible by our Sponsors

Gold

DavinsiLabs.png Vest.jpg


Silver

LogoIngenicoGroup.png LogoToreon.jpg LogoSynopsys.png Nviso logo RGB baseline 200px.png


Bronze

Logo Informatiebeveiliging-200.png