This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP BeNeLux-Days 2018"
From OWASP
(→Woman in cybersecurity (CyberWayFinder)) |
|||
(36 intermediate revisions by 6 users not shown) | |||
Line 6: | Line 6: | ||
<!-- First tab --> | <!-- First tab --> | ||
= Information = | = Information = | ||
− | |||
− | |||
− | {{#switchtablink: | + | <p style="text-align:center">'''Thanks to all speakers and trainers, sponsors and volunteers who could make this 2018 edition a success.<br>'''</p> |
− | + | ||
− | + | Sad you missed the conference? No problem, just have a look at the {{#switchtablink:Conference_Day|video recordings}}! | |
− | - | + | |
+ | |||
+ | == Save the date == | ||
+ | |||
+ | <p style="text-align:center"><font color="red">'''In 2019 we will skip one year (we organised Global AppSec Amsterdam), See you next year in the Netherlands: 26 and 27 November 2020'''</font></p> | ||
+ | |||
== Confirmed Conference Speakers == | == Confirmed Conference Speakers == | ||
Line 43: | Line 46: | ||
== OWASP BeNeLux conference is free, but registration is required! == | == OWASP BeNeLux conference is free, but registration is required! == | ||
− | + | The conference is closed.<br> | |
− | |||
'''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.''' | '''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.''' | ||
Line 52: | Line 54: | ||
* Sebastien Deleersnyder / Lieven Desmet / David Mathy / Thomas Herlea / Stella Dineva / Adolfo Solero / Bart De Win, [[Belgium|OWASP Belgium]] | * Sebastien Deleersnyder / Lieven Desmet / David Mathy / Thomas Herlea / Stella Dineva / Adolfo Solero / Bart De Win, [[Belgium|OWASP Belgium]] | ||
− | * Martin Knobloch / Joren Poll / Edwin | + | * Martin Knobloch / Joren Poll / Edwin Gozeling, [[Netherlands|OWASP Netherlands]] |
* [[Luxembourg|OWASP Luxembourg]] | * [[Luxembourg|OWASP Luxembourg]] | ||
Line 66: | Line 68: | ||
= Registration = | = Registration = | ||
− | == | + | == Registration is closed == |
− | |||
− | |||
− | |||
'''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.''' | '''To support the OWASP organisation, consider to become a member, it's only US$50! Check out the [[Membership]] page to find out more.''' | ||
Line 79: | Line 78: | ||
== Address == | == Address == | ||
− | + | <table width="100%"> | |
+ | <tr valign="top"> | ||
+ | <td width="50%"> | ||
+ | === Training venue === | ||
+ | |||
+ | '''Novotel Mechelen Centrum''' | ||
+ | Van Beethovenstraat 1 | ||
+ | 2800 Mechelen | ||
+ | Belgium | ||
+ | |||
+ | [https://goo.gl/maps/WxErtbWADqC2 Google maps] | ||
+ | </td> | ||
+ | <td width="50%"> | ||
+ | === Conference venue === | ||
'''Congres- en Erfgoedcentrum Lamot''' | '''Congres- en Erfgoedcentrum Lamot''' | ||
Line 87: | Line 99: | ||
[https://goo.gl/maps/gZ9icR178w52 Google map] | [https://goo.gl/maps/gZ9icR178w52 Google map] | ||
+ | |||
+ | </td> | ||
+ | </tr> | ||
+ | </table> | ||
<br /> | <br /> | ||
[[File:Mechelen-Lamot.jpg|350px|Lamot conference center]] | [[File:Mechelen-Lamot.jpg|350px|Lamot conference center]] | ||
[[File:Mechelen-lamot-center-auditorium.jpg|350px|Auditorium]]<br /> | [[File:Mechelen-lamot-center-auditorium.jpg|350px|Auditorium]]<br /> | ||
+ | |||
+ | |||
Parking:<br /> | Parking:<br /> | ||
Line 118: | Line 136: | ||
<!-- Fourth tab --> | <!-- Fourth tab --> | ||
+ | |||
= Training Day = | = Training Day = | ||
'''Training Day is November 29th''' | '''Training Day is November 29th''' | ||
+ | |||
+ | == Training Venue == | ||
+ | |||
+ | The trainings will take place in the '''Novotel Mechelen Centrum''' hotel:<br> | ||
+ | Van Beethovenstraat 1<br> | ||
+ | 2800 Mechelen<br> | ||
+ | [https://goo.gl/maps/WxErtbWADqC2 Google maps] | ||
+ | |||
== Agenda== | == Agenda== | ||
{| class="wikitable" | {| class="wikitable" | ||
! Time !! Description !! Training 1 !! Training 2 !! Training 3 | ! Time !! Description !! Training 1 !! Training 2 !! Training 3 | ||
+ | |- | ||
+ | ! !! !! (Hof van Busleyden 1) !! (Hof van Busleyden 2) !! (Hof van Kamerijk) | ||
|- | |- | ||
| 08h30 - 9h30 | | 08h30 - 9h30 | ||
− | | | + | | style="text-align: center; background: grey; color: white;" colspan="5" | ''Registration'' |
|- | |- | ||
| 09h30 - 11h00 || Training | | 09h30 - 11h00 || Training | ||
− | | | + | | style="width:100px;" rowspan="7" | [[#TRAINING_1 | Kubernetes security]] by Andrew Martin |
− | | | + | | style="width:100px;" rowspan="7" | [[#TRAINING_2 | OWASP Zap Training]] by David Scrobonia |
− | | | + | | style="width:100px;" rowspan="7" | [[#TRAINING_3 | Android security workshop]] by Jeroen Beckers & Stephanie Vanroelen |
|- | |- | ||
| 11h00 - 11h30 || ''Coffee Break'' | | 11h00 - 11h30 || ''Coffee Break'' | ||
Line 169: | Line 198: | ||
===== Who Should Attend ===== | ===== Who Should Attend ===== | ||
This course is suitable for intermediate to advanced Kubernetes users who want to strengthen their security understanding. It is particularly beneficial for those operating Kubernetes in a high-compliance domain, or for established security professionals looking to update their skills for the cloud native world. | This course is suitable for intermediate to advanced Kubernetes users who want to strengthen their security understanding. It is particularly beneficial for those operating Kubernetes in a high-compliance domain, or for established security professionals looking to update their skills for the cloud native world. | ||
+ | |||
+ | ===== Participant requirements ===== | ||
+ | Just a laptop with an SSH client please, ssh or PuTTY. | ||
==== Bio ==== | ==== Bio ==== | ||
Line 190: | Line 222: | ||
# Using ZAP within your CI/CD Pipeline | # Using ZAP within your CI/CD Pipeline | ||
+ | ===== Participant requirements ===== | ||
+ | Please come prepared with the following tools installed: | ||
+ | * ZAP (https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-270-standard) | ||
+ | * docker | ||
+ | |||
+ | If you have any trouble with the setup please feel free to reach out to davidscrobonia at gmail with questions. | ||
+ | |||
==== Bio ==== | ==== Bio ==== | ||
Line 227: | Line 266: | ||
<!-- Fifth tab --> | <!-- Fifth tab --> | ||
− | |||
= Conference Day = | = Conference Day = | ||
Line 238: | Line 276: | ||
! width="190pt" | Speaker | ! width="190pt" | Speaker | ||
! width="400pt" | Topic | ! width="400pt" | Topic | ||
− | + | ! width="100pt" | Media | |
|- | |- | ||
| 08h30 - 09h15 | | 08h30 - 09h15 | ||
− | | | + | | style="text-align: center; background: grey; color: white" colspan="3" | ''Registration / [[#CyberWayFinder | Women in cybersecurity (CyberWayFinder)]]'' |
|- | |- | ||
| 09h15 - 09h30 | | 09h15 - 09h30 | ||
− | | | + | | style="text-align: center; background: grey; color: white" colspan="3" | ''Opening'' |
|- | |- | ||
| 09h30 - 10h15 | | 09h30 - 10h15 | ||
| [[#TALK_0930 | Lennert Wouters]] | | [[#TALK_0930 | Lennert Wouters]] | ||
| [[#TALK_0930 | Fast, Furious and Insecure: Passive Keyless Entry and Start in Modern Supercars]] | | [[#TALK_0930 | Fast, Furious and Insecure: Passive Keyless Entry and Start in Modern Supercars]] | ||
− | + | | | |
|- | |- | ||
| 10h15 - 11h00 | | 10h15 - 11h00 | ||
| [[#TALK_1015 | Ralph Moonen]] | | [[#TALK_1015 | Ralph Moonen]] | ||
| [[#TALK_1015 | Weaknesses in our voice communications network: from Blue Boxing to VoLTE]] | | [[#TALK_1015 | Weaknesses in our voice communications network: from Blue Boxing to VoLTE]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 Ralph Moonen - Weaknesses in our voice communications network - from Blue Boxing to VoLTE compressed.pdf | Slides]]<br> | |
+ | [https://youtu.be/Rl7VabjEd_A Video] | ||
|- | |- | ||
| 11h00 - 11h30 | | 11h00 - 11h30 | ||
− | | | + | | style="text-align: center;background: grey; color: white" colspan="3" | ''Morning Break'' |
|- | |- | ||
| 11h30 - 12h15 | | 11h30 - 12h15 | ||
| [[#TALK_1130 | Niels Tanis]] | | [[#TALK_1130 | Niels Tanis]] | ||
| [[#TALK_1130 | When Serverless Met Security… Serverless Security & Functions-as-a-Service (FaaS)]] | | [[#TALK_1130 | When Serverless Met Security… Serverless Security & Functions-as-a-Service (FaaS)]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 Niels Tanis - When Serverless Met Security.pdf | Slides]] <br> | |
+ | [https://youtu.be/wuvGmXN0n6Q Video] | ||
|- | |- | ||
| 12h15 - 13h00 | | 12h15 - 13h00 | ||
| [[#TALK_1215 | David Scrobonia]] | | [[#TALK_1215 | David Scrobonia]] | ||
| [[#TALK_1215 | OWASP Zap]] | | [[#TALK_1215 | OWASP Zap]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 David Scrobonia OWASP Zap.pdf | Slides]]<br> | |
+ | [https://youtu.be/iaZaPuQ6ams Video] | ||
|- | |- | ||
| 13h00 - 14h00 | | 13h00 - 14h00 | ||
− | | | + | | style="text-align: center;background: grey; color: white" colspan="3" | ''Lunch'' |
|- | |- | ||
| 14h00 - 14h45 | | 14h00 - 14h45 | ||
| [[#TALK_1400 | Björn Kimminich]] | | [[#TALK_1400 | Björn Kimminich]] | ||
| [[#TALK_1400 | Juice Shop: OWASP's most broken Flagship]] | | [[#TALK_1400 | Juice Shop: OWASP's most broken Flagship]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 Bjoern Kimminich - Juice Shop - OWASP's most broken Flagship.pdf | Slides]]<br> | |
+ | [https://youtu.be/Lu0-kDdtVf4 Video] | ||
|- | |- | ||
| 14h45 - 15h30 | | 14h45 - 15h30 | ||
| [[#TALK_1445 | Jo Van Bulck]] | | [[#TALK_1445 | Jo Van Bulck]] | ||
| [[#TALK_1445 | Leaky Processors: Stealing Your Secrets with Foreshadow]] | | [[#TALK_1445 | Leaky Processors: Stealing Your Secrets with Foreshadow]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 Jo Van Bulck - Leaky Processors - Stealing Your Secrets with Foreshadow.pdf | Slides]] <br> | |
+ | [https://youtu.be/le60NzmxU6s Video] | ||
|- | |- | ||
| 15h30 - 16h00 | | 15h30 - 16h00 | ||
− | | | + | | style="text-align: center;background: grey; color: white" colspan="3" | ''Afternoon Break'' |
|- | |- | ||
| 16h00 - 16h45 | | 16h00 - 16h45 | ||
| [[#TALK_1600 | Jeroen Willemsen]] | | [[#TALK_1600 | Jeroen Willemsen]] | ||
| [[#TALK_1600 | Fast forwarding Mobile Security with the MSTG]] | | [[#TALK_1600 | Fast forwarding Mobile Security with the MSTG]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 Jeroen Willemsen - Fast forwarding Mobile Security with the MSTG compressed.pdf | Slides ]]<br> | |
+ | [https://youtu.be/WI2_cP48TnA Video] | ||
|- | |- | ||
| 16h45 - 17h30 | | 16h45 - 17h30 | ||
| [[#TALK_1645 | Nick Drage]] | | [[#TALK_1645 | Nick Drage]] | ||
| [[#TALK_1645 | Lessons from the legion (The OWASP BeNeLux Remix)]] | | [[#TALK_1645 | Lessons from the legion (The OWASP BeNeLux Remix)]] | ||
− | + | | [[Media:OWASP BeNeLux 2018 Nick Drage - Lessons from the Legion compressed.pdf | Slides]]<br> | |
+ | [https://youtu.be/516Z420BgkE Video] | ||
|- | |- | ||
| 17h30 - 17h45 | | 17h30 - 17h45 | ||
− | | | + | | style="text-align: center;background: grey; color: white" colspan="3" | ''Closing'' |
|} | |} | ||
Line 399: | Line 444: | ||
==== Abstract ==== | ==== Abstract ==== | ||
− | After the startup of the mobile security project in 2010, the mobile security project and its testing guides have seen quiet some evolution. All of this changed quiet intensively when, in 2016, the Mobile Application Security Verification Standard (MASVS) and the Mobile Application Security Testing Guide (MSTG) were created. Now, two years fast forward: where are we now? How can you use it as a pentester or a developer? We will start with introducing the current state of the MSTG and its side-projects and then show various demos on iOS | + | After the startup of the mobile security project in 2010, the mobile security project and its testing guides have seen quiet some evolution. All of this changed quiet intensively when, in 2016, the Mobile Application Security Verification Standard (MASVS) and the Mobile Application Security Testing Guide (MSTG) were created. Now, two years fast forward: where are we now? How can you use it as a pentester or a developer? We will start with introducing the current state of the MSTG and its side-projects and then show various demos on iOS.<br> |
==== Bio ==== | ==== Bio ==== | ||
− | Jeroen Willemsen is a Principal Security Architect at Xebia. With a love for mobile security, he recently became one of the projectleaders for the OMTG project ( | + | Jeroen Willemsen is a Principal Security Architect at Xebia. With a love for mobile security, he recently became one of the projectleaders for the OMTG project (MASVS & MSTG). Jeroen is more or less a jack of all trades with interest in infrastructure security, risk management and application security. |
=== <span id="TALK_1645">Lessons From The Legion (The OWASP BeNeLux Remix) by Nick Drage</span> === | === <span id="TALK_1645">Lessons From The Legion (The OWASP BeNeLux Remix) by Nick Drage</span> === | ||
Line 440: | Line 485: | ||
'''Any participant pays individually. <br>Reservation via the form you'll receive after conference registration is mandatory.'''<br> | '''Any participant pays individually. <br>Reservation via the form you'll receive after conference registration is mandatory.'''<br> | ||
− | |||
− | |||
− | |||
Line 471: | Line 513: | ||
[[File:DavinsiLabs.png|250px|link=https://www.davinsilabs.com]] | [[File:DavinsiLabs.png|250px|link=https://www.davinsilabs.com]] | ||
− | [http://www.vest.nl | + | [[File:Vest.jpg|250px|link=http://www.vest.nl]] |
Line 480: | Line 522: | ||
[[File:LogoSynopsys.png|250px|link=https://www.synopsys.com]] | [[File:LogoSynopsys.png|250px|link=https://www.synopsys.com]] | ||
[[File:Nviso_logo_RGB_baseline_200px.png|250px|link=http://www.nviso.be]] | [[File:Nviso_logo_RGB_baseline_200px.png|250px|link=http://www.nviso.be]] | ||
− | |||
Line 486: | Line 527: | ||
==== Bronze ==== | ==== Bronze ==== | ||
− | [https://informatiebeveiliging.nl/ | + | [[File:Logo_Informatiebeveiliging-200.png|250px|link=https://informatiebeveiliging.nl/]] |
− | |||
[[Category:OWASP_AppSec_Conference]] | [[Category:OWASP_AppSec_Conference]] | ||
[[Category:OWASP_BeNeLux_Archives]] | [[Category:OWASP_BeNeLux_Archives]] |
Latest revision as of 13:42, 31 October 2019

Made possible by our Sponsors
Gold
Silver