|
|
| (2 intermediate revisions by the same user not shown) |
| Line 1: |
Line 1: |
| − | 7/3 12:00pm ~ Currently I am moving speakers around, making room and adjustments, when done
| |
| − | i will simple REPLACE the agenda [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference currently posted] with this one
| |
| − | and kill this placeholder page... special requests can be accommodated by calling 973-795-1046 x112
| |
| − | - brennan
| |
| − | <hr>
| |
| | | | |
| − | | + | This page is no longer being used... |
| − | == 2008 OWASP USA, NYC Conference Schedule – Sept 24th - Sept 25th ==
| |
| − | <center>[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference/speakeragreement OWASP Speaker Agreement]</center>
| |
| − | {| style="width:80%" border="0" align="center"
| |
| − | ! colspan="4" align="center" style="background:#4058A0; color:white" | Day 1 – Sept 24th, 2008
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | || style="width:30%; background:#BC857A" | Track 1:
| |
| − | | style="width:30%; background:#BCA57A" | Track 2:
| |
| − | | style="width:30%; background:#99FF99" | Track 3:
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 07:30-10:00 || colspan="3" style="width:80%; background:#C2C2C2" align="center" | '''Doors Open for Attendee/Speaker Registration & [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference#Technology_Pavilion_-_September_24th_and_25th Exhibit/Sponsor Area]'''
| |
| − | | |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 09:00-09:45 || colspan="3" style="width:80%; background:#F2F2F2" align="center" | OWASP Version 3.0 who we are, where we are.. where we are going
| |
| − | ''[http://www.owasp.org/index.php/Contact OWASP Foundation]: Jeff Williams, Dinis Cruz, Dave Wichers, Tom Brennan, Sebastien Deleersnyder, Paolo Perego, Kate Hartmann & Alison Shrader
| |
| − | ''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 10:00-10:45 || style="width:30%; background:#BC857A" align="left" | [http://www.owasp.org/index.php/AppSecEU08_Trends_in_Web_Hacking_Incidents:_What%27s_hot_for_2008 Analysis of the Web Hacking Incidents Database (WHID)]
| |
| − | ''[http://blog.shezaf.com Ofer Shezaf]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | [http://www.webappsecroadmap.com Web Application Security Road Map] <br>
| |
| − | ''[http://joesecurity.blogspot.com Joe White]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | Got Security?
| |
| − | ''[http://www.krvw.com/about/about.html Kenneth R. van Wyk]''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 11:00-11:45 || style="width:30%; background:#BC857A" align="left" | Web Security Education using Open Source Tools
| |
| − | ''Prof. Li-Chiou Chen & Chienitng Lin, [http://www.pace.edu/page.cfm?doc_id=16399 Pace Univ]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Http Bot Research
| |
| − | ''[http://www.shadowserver.org/wiki/pmwiki.php?n=Shadowserver.Mission Andre M. DiMino - ShadowServer Foundation]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | MalSpam Research
| |
| − | '' [http://www.knujon.com/bios.html Garth Bruen]''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 12:00-13:00 || colspan="3" style="width:80%; background:#F2F2F2" align="center" | [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference/ctf Capture the Flag] Sign-Up
| |
| − | ''LUNCH - Provided by event sponsors @ TechExpo''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 13:00-13:45 || style="width:30%; background:#BC857A" align="left" | Offensive Assessing Financial Applications
| |
| − | '' [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference-daniel-cuthbert Daniel Cuthbert]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | WAF ModSecurity
| |
| − | ''[http://www.thinkingstone.com/about/ivan-ristic.html Ivan Ristic]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | OWASP & NYC
| |
| − | ''[http://www.linkedin.com/in/davidstern2000 David Stern]''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 14:00-14:45 || style="width:30%; background:#BC857A" align="left" | Logic Attacks and Inefficiencies of Robotic Detection
| |
| − | ''[http://ha.ckers.org/blog/about Robert "RSnake" Hansen], CEO SecTheory''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Reverse Engineering .NET
| |
| − | ''Adam Boulton''
| |
| − | | style="width:30%; background:#99FF99" align="left" | JBroFuzz 0.1 - 1.1: Building a Java Fuzzer for the Web
| |
| − | ''[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference-SPEAKER-Yiannis_Pavlosoglou Yiannis Pavlosoglou]''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 15:00-15:45 || style="width:30%; background:#BC857A" align="left" |Industry Panel w/ Jennifer Bayuk CISO Bear Stearns, Mark Clancy EVP CitiGroup, Jim Routh CISO DTCC, Sunil Seshadri CISO NYSE-Euronet, Warren Axelrod SVP Bank of America, Joe Bernik Royal Bank of Scotland & Philip Venables CIRO, Goldman, Sachs
| |
| − | | style="width:30%; background:#BCA57A" align="left" | [http://www.owasp.org/index.php/Wild_Wild_Web_on_Security_Planet Wild Wild Web on Security Planet]
| |
| − | ''[http://www.expresscertifications.com/company/execmgt.aspx Mano Paul] CEO Express Certifications''
| |
| − | | style="width:30%; background:#99FF99" align="left" |[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference-SPEAKER-GunterOllmann Multidisciplinary Bank Attacks]
| |
| − | ''Gunter Ollmann''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 16:00-16:45 || style="width:30%; background:#BC857A" align="left" | OWASP Enterprise Security API [http://www.owasp.org/index.php/ESAPI (ESAPI) Project]
| |
| − | '' [http://www.aspectsecurity.com/management.htm Jeff Williams]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Shootout @ Blackbox Corral
| |
| − | ''Larry Suto ''
| |
| − | | style="width:30%; background:#99FF99" align="left" | 80% 10% 10%
| |
| − | '' [http://www.blogger.com/profile/07177656204885181542 Andy Steingruebl], Security @ PayPal''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 17:00-17:45 || style="width:30%; background:#BC857A" align="left" | Threading the Needle:
| |
| − | | |
| − | Bypassing web application/service security controls using Encoding, Transcoding, Filter Evasion, and other Canonicalization Attacks
| |
| − | '' [http://www.linkedin.com/in/arianevans Arian Evans]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" |Shhhh Don’t Tell Anybody
| |
| − | ''[http://www.linkedin.com/in/ppetkov Petko D. Petkov]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference-SPEAKER-Andres_Riancho W3AF Open Source App Scanner]
| |
| − | ''Andres Riancho''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 18:00-18:45 || style="width:30%; background:#BC857A" align="left" | [http://www.owasp.org/index.php/Category:OWASP_Live_CD_Project OWASP Live CD]
| |
| − | '' [http://www.linkedin.com/in/packetfocus Joshua Perrymon]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Coding Secure w/PHP
| |
| − | ''[http://www.linkedin.com/in/zaunere Hans Zaunere]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | [http://www.owasp.org/index.php/Payment_Card_Data_Security_and_the_new_Enterprise_Java Payment Card Data Security and the new Enterprise Java]
| |
| − | ''Dr. B. V. Kumar & Mr. Abhay Bhargav''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 20:00-23:00 || colspan="3" style="width:80%; background:#C2C2C2" align="center" | OWASP NYC AppSec 2008 VIP Party
| |
| − | ''Location: TBD''
| |
| − | |-
| |
| − | ! colspan="10" align="center" style="background:#4058A0; color:white" | Day 2 – Sept 25th, 2008
| |
| − | |-
| |
| − | | style="width:10%; background:#99FF99" | 08:00-10:00 || colspan="3" style="width:80%; background:#F2F2F2" align="center" | BREAKFAST - Provided by event sponsors @ TechExpo
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 0800-08:45 || colspan="3" style="width:80%; background:#C2C2C2" align="center" | [http://www.aeispeakers.com/speakerbio.php?SpeakerID=1192 Prof. Howard A. Schmidt, CISSP, CISM (Hon.)] |
| |
| − | Current (ISC)² Security Strategist and Former White House Cyber Security Advisor
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 09:00-09:45 || style="width:30%; background:#BC857A" align="left" | Good vs. Evil JavaScript
| |
| − | ''[http://jeremiahgrossman.blogspot.com Jeremiah Grossman]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | OWASP V2 Testing Guide 4.2.3 Spidering and Googling in depth
| |
| − | ''[http://www.linkedin.com/in/ChristianHeinrich Christian Heinrich]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | Web Security Education using Open Source Tools
| |
| − | ''Prof. Li-Chiou Chen & Chienitng Lin of Pace Univ.''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 10:00-10:45 || style="width:30%; background:#BC857A" align="left" | OWASP Update
| |
| − | ''Dinis Cruz/Jeff Williams + Surprise Guest''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | OWASP Topic
| |
| − | ''SPEAKER TBD''
| |
| − | | style="width:30%; background:#99FF99" align="left" | OWASP Topic
| |
| − | ''Speaker TBD''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 11:00-11:45 || style="width:30%; background:#BC857A" align="left" | [http://www.owasp.org/index.php/Category:OWASP_CLASP_Project CLASP (Comprehensive, Lightweight Application Security Process)]
| |
| − | ''Pravir Chandra''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Next Generation Cross Site Scripting Worms
| |
| − | ''[http://i8jesus.com/?page_id=5 Arshan Dabirsiaghi]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | Secure Software Impact
| |
| − | ''[http://ouncelabs.com/company/team.asp Jack Danahy]''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 12:00-12:45 || style="width:30%; background:#BC857A" align="left" | Security in Agile Development
| |
| − | ''[http://www.owasp.org/index.php/User:Wichers Dave Wichers]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Security of Software-as-a-Service (SaaS)
| |
| − | ''[http://www.linkedin.com/pub/6/372/45a James Landis]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | [http://reversebenchmarking.com/About.html Open Reverse Benchmarking Project]
| |
| − | ''Marce Luck & [http://www.linkedin.com/pub/1/507/616 Tom Stracener] ]''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 12:00-13:00 || colspan="3" style="width:80%; background:#F2F2F2" align="center" | ''LUNCH - Provided by event sponsors @ TechExpo''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 13:00-13:45 || style="width:30%; background:#BC857A" align="left" | Security Research Report
| |
| − | ''[http://www.linkedin.com/pub/5/742/233 Dinis Cruz]''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | [http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project Pantera Advances]
| |
| − | ''[http://www.linkedin.com/pub/1/598/855 Simon Roses Femerling]''
| |
| − | | style="width:30%; background:#99FF99" align="left" | Lotus Notes Insecurity
| |
| − | ''Jian Hui Wang''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 14:00-14:45 || style="width:30%; background:#BC857A" align="left" | Practical Advanced Threat Modeling
| |
| − | ''John Steven''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon]
| |
| − | ''Paolo Perego''
| |
| − | | style="width:30%; background:#99FF99" align="left" | Building Usable Security
| |
| − | ''Zed Abbadi''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 15:00-15:45 || style="width:30%; background:#BC857A" align="left" | [http://www.owasp.org/index.php/Input_validation:_the_Good%2C_the_Bad_and_the_Ugly Input validation: the Good, the Bad and the Ugly]
| |
| − | ''Johan Peeters''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Offshoring Application Development? Security is Still Your Problem
| |
| − | ''Rohyt Belani''
| |
| − | | style="width:30%; background:#99FF99" align="left" | NIST SAMATE Static Analysis Tool Exposition (SATE)
| |
| − | ''Vadim Okun''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 16:00-16:45 || style="width:30%; background:#BC857A" align="left" | TOPIC
| |
| − | ''SPEAKER''
| |
| − | | style="width:30%; background:#BCA57A" align="left" | Flash Parameter Injection (FPI)
| |
| − | ''Ayal Yogev & Yuval Baror''
| |
| − | | style="width:30%; background:#99FF99" align="left" | Cross-Site Scripting Filter Evasion
| |
| − | ''Alexios Fakos''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 17:00-17:45 || colspan="3" style="width:80%; background:#C2C2C2" align="center" | '''Wizdom of Crowds / CTF Awards & Raffles'''
| |
| − | |-
| |
| − | | style="width:10%; background:#7B8ABD" | 18:30-19:30 || colspan="3" style="width:80%; background:#C2C2C2" align="center" | OWASP Foundation, Chapter Leader Meeting
| |
| − | |}
| |
| − | | |
| − | More information below
| |
This page is no longer being used...