This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Morocco"

From OWASP
Jump to: navigation, search
m
 
(94 intermediate revisions by 4 users not shown)
Line 1: Line 1:
==== OWASP Morocco Presentation  ====
+
[[File:AppSec-MA-2018.PNG|600px|thumb|left|]][[File:Mosquee_Hassan_II.PNG|400px|thumb|center|]]
 +
= OWASP Morocco Presentation  =
  
{{Chapter Template|chaptername=Morocco|extra= The chapter leader is [mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-morocco|emailarchives=http://lists.owasp.org/pipermail/owasp-morocco}}  
+
Scope of the board is to discuss and approve local activities, meetings and plans.
 +
 
 +
{{Chapter Template|chaptername=Morocco|extra=  
 +
The chapter Leader is <br>[mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI]<br>
 +
 
 +
<br> Morocco Chapter co-leaders and team member<br>
 +
 
 +
[mailto:tarik.elaouadi(at)owasp.org Tarik EL AOUADI]<br>
 +
[mailto:Alaeddine.Mesbahi(at)gmail.com Alaeddine MESBAHI]<br>
 +
 
 +
<br> Board member of Morocco Chapter<br>
 +
[mailto:a.eljai(at)adamridson.com Abdessalem ELJAI]<br>
 +
[mailto:othmane.erraji(at)amge-caravane.com  Othmane ERRAJI]<br>
 +
[mailto:ramramilamya(a)gmail.com LAMIYA Ramrami]<br>
 +
 
 +
 
 +
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-morocco|emailarchives=http://lists.owasp.org/pipermail/owasp-morocco}}  
 +
 
 +
== Contacts et Propositions de Présentations/Contributions ==
 +
 
 +
*[mailto:Azzeddine.RAMRAMI(at)owasp.org Azzeddine RAMRAMI] et [mailto:tarik.elaouadi(at)owasp.org Tarik EL AOUADI] sont à votre disposition si vous souhaitez des informations sur l'OWASP ainsi que sur la Sécurité des Applications Web.
 +
 
 +
Entreprises, Individuels, Monde Académique, Sponsors, Supports, tout le monde est bienvenu à l'OWASP.
 +
 
 +
Pour les Entreprises souhaitant adhérer à l'OWASP, le montant de l'adhésion annuelle de $5000 US (dont 40% est reversé au Chapitre de votre choix) est 100% déductible!
 +
 
 +
Les fonds collectés servent à organiser les meetings du Chapitre Marocain, mais aussi et surtout à construire et organiser avec vous une approche spécifique en fonction de vos souhaits (sessions de sensibilisation, meetings internes, interventions de Speakers, etc.). Tout cela peut être discuté avec le Chapitre Marocain et acté conjointement avec vous si vous souhaitez adhérer à l'OWASP.
 +
 
 +
N'hésitez pas à nous solliciter si vous souhaitez discuter d'un sujet particulier, ou si vous souhaitez effectuer une présentation lors d'un meeting du Chapitre Marocain.
 +
 
 +
Amis de la Presse écrite et du Multimédia, n'hésitez pas à faire appel à nous si vous souhaitez notre concours pour vos articles et reportages, vous êtes les bienvenus et nous en serions honorés. Nous avons nous aussi besoin de vous.
 +
 
 +
Moi et le board du Chapitre Marocain restons modestes dans notre approche, mais nous souhaitons vraiment que le Chapitre OWASP Maroc devienne un de vos contacts de référence.
 +
 
 +
 
 +
= Meetings 2019 =
 +
 
 +
== February 2019 Q1/2019 ==
 +
 
 +
=== OWASP Training Day at ONCF,  15th February 2019 in Rabat/Morocco ===
 +
Azzeddine RAMRAMI will run a one full day developper training on OWASP, on 15th February 2019. 
 +
 
 +
OWASP Morocco Chapter members running this session:
 +
 
 +
Azzeddine RAMRAMI
 +
 
 +
Abdessamad TEMMAR
 +
 
 +
Abdessalam EL JAY
 +
 
 +
'''Location''': ONCF Club
 +
 
 +
'''City''': Rabat
 +
 
 +
'''Country''': Morocco
 +
 
 +
'''Course Outline:'''
 +
* 1)        Introductions
 +
* 2)        Agenda
 +
* 3)        Secure Development Lifecycle (SDLC)
 +
* 4)        Lab: Threat Modeling
 +
* 5)        Principles of Secure Code
 +
* 6)        Authentication & Authorization
 +
* 7)        Lab: Access Control
 +
* 8)        Mini-Lab: Weak Session Identifiers
 +
* 9)        Session Management
 +
* 10)      Lab: SQL Injection
 +
* 11)      Lab: Cross-Site Scripting
 +
* 12)      Input Validation
 +
* 13)      Lab: SQL Injection Patching
 +
* 14)      Lab: Cross-Site Scripting Patching
 +
* 15)      Proper Encryption
 +
* 16)      Mini-Lab: Hash Breaking
 +
* 17)      Logic Flaws
 +
* 18)      Lab: Logic Flaw Exploitation
 +
* Addition Labs:
 +
* 19)      Other Attacks
 +
* 20)      Mini-Lab: XML Attacks
 +
* 21)      Security Hygiene
 +
* 22)      Final Lab: Hacking Contest
 +
 
 +
'''Sponsor of this event:'''  MUNISYS (http://www.munisys.net.ma/)
 +
 
 +
== June 2019 Q2/2019 ==
 +
 
 +
=== OWASP Training Day at Mohammed VI Polytechnic University on June 27th, 2019 in Ben Guerir  Marrakech/Morocco ===
 +
Azzeddine RAMRAMI with OWASP Morocco Team will run one full day developper training on workshop OWASP, on 27th June 2019. 
 +
 
 +
This session will run by Azzeddine RAMRAMI, Abdessalam ELJAI and Othmane TAGAMART. 
 +
 
 +
'''Location''': Universite Mohamed VI Bengruir
 +
 
 +
'''City''': Ben Guerir / UM6P
 +
 
 +
AdresseMohammed VI Polytechnic University 
 +
 
 +
Lot 660, Hay Moulay Rachid Ben Guerir, 43150, Morocco
 +
 
 +
'''Country''': Morocco
 +
 
 +
'''Workshop Outline: Two sessions'''
 +
* Introduction à l'OWASP: Abdessalam JAY                                                                                                                09h00 - 09h30 
 +
* L'état de l'art de la sécurité IoT: Othmane TAMAGARTI                                                                                            09h30 - 10h30  
 +
* Pause café                                                                                                                                                                 10h30 - 11h00 
 +
* Secure Coding Java & .NET with OWASP TOP 10 2017 Part 1: Azzeddine RAMRAMI & Othmane TAMAGART   11h00 - 13h00 
 +
* Pause déjeuner                                                                                                                                                          13h00 - 14h00 
 +
* Secure Coding Java & .NET with OWASP TOP 10 2017 Part 2: Azzeddine RAMRAMI & Othmane TAMAGART   14h00 - 16h00   
 +
* Pause café                                                                                                                                                                 16h00 - 16h30 
 +
* Secure Coding Java & .NET with OWASP TOP 10 2017 Part 3: Azzeddine RAMRAMI & Othmane TAMAGART   16h30 - 18h00  
 +
'''Contact to subscription: <br>[mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI]<br>'''[[Morocco|https://www.owasp.org/index.php/Morocco#tab=Meetings_2019]]
  
= Morocco OWASP Chapter Board =
+
'''Sponsor of this event:'''  [https://www.adamridson.com Adam Ridson]
  
Scope of the board is to discuss and approve local activities, meetings and plans.  
+
= Past Meeting Meetings 2018 =
 +
 
 +
=== Welcome to the second edition of OWASP AppSec Morocco and Africa in Casablanca, Hotel Val d'Anfa on November 15-16, 2018. ===
 +
https://2018.appsecmorocco.org/agenda/
 +
 
 +
At AppSec Morocco & Africa you can connect with over 250 security professionals in our sponsor hall. Our floor plan is designed to allow you to engage with speakers and attendees.
  
In alphabetical order:  
+
Thank you to the Sponsors of Appsec Morocco & Africa 2018 :
  
*Chapter Leader [mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI]
+
https://2018.appsecmorocco.org/sponsors/
*Pôle Sécurité PenTest [mailto:hamza.waraki(at)owasp.org Hamza WARAKI]
 
*Labo Sécurity and hacking at VINCI  [mailto:hackers(at)vincispace.net Intissar EL MEZROUI]
 
*Pôle Sécurité PenTest [mailto:Nawfal.Makdad(at)owasp.org Nawfal Makdad]
 
*Responsable du pôle Sécurité Applicative [mailto:tarik.elaouadi(at)owasp.org Tarik El Aouadi]
 
  
= Chapter Meetings  =
+
Here the final list of our speakers from differents countries including Africa (Morocco and Algerie), Canada, Europe and Asia.
  
== Web Application Security Seminar - May 18<sup>th</sup>, 2012 - at  VINCI School Rabat/Morocco ==
+
https://2018.appsecmorocco.org/speakers/
  
*'''MAIN PRESENTERS:''' Azzeddine RAMRAMI: OWASP Leader, Hamza WARAKI: Pôle Sécurité PenTest OWASP Morocco, Tarif EL AOUADI from Lexi and Intissar from VINCI<br>
+
= Meetings 2017 =
*'''ABSTRACT:''' During this seminars Azzeddine RAMRAMI will present a complete Architecture Security Framework to implement Web Application Security the IT landscape. Hamza WARAKI will present how to conduct an OWASP Web Application PenTesting. OWASP activity and spirit will be presented in this event.
 
*'''WHEN: '''May 18<sup>th</sup>, 2012
 
*'''WHERE:''' VINCI Ecole Supérieure Rabat/Morocco see&nbsp;[http://www.vinci.ma/ VINCI Ecole Supérieure Rabat]<br>
 
''' 10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected]<br>
 
  
*'''REGISTRATION:
+
== OWASP AppSec Africa 2017 ==
'''At AXEL TELECOM ([http://www.axeltelecom.fr/index.php/ressources/seminaire-owsap Axel Telecom])
 
'''or at VINCI  ([http://www.vinci.ma VINCI Ecole Supérieure])
 
*'''PROGRAM:'''
 
09:00-09:30 Welcome<br>
 
09:30-09:45 OWASP Presentation ( Azzeddine RAMRAMI )<br>
 
09:45-10:00 Security Awarnasse ( Tarik EL AOUADI )<br>
 
10:00-10:30 OSSTMM v3.0 a PenTest Methodlogy - Overview ( Intissar EL MEZROUI )<br>
 
10:30-10:45 PAUSE<br>
 
10:45-11:30 How to conduct a Web Application Pen Testing ( Hamza WARRAKI)<br>
 
11:30-12:00 OWASP WebGoat & Attack Example (A virtual Hacking Environnement)  (Nawfal Makdad )<br>
 
12:00-14:30 PRIERE DE VENDREDI<br>
 
14:30-15:30 OWASP WebGoat & Attack Example (A virtual Hacking Environnement)  (Nawfal Makdad )<br>
 
15:30-16:15 Smartphone Security (Tarik EL OUADI)<br>
 
16:15-16:30 PAUSE <br>
 
16:30-17:00 Smartphone Security (Tarik EL AOUADI) <br>
 
17:00-17:45 Writing Secure Code : Java Principles ( Azzeddine RAMRAMI )<br>
 
17:45-18:00 Questions & Answers<br>
 
  
*'''Event Flyer :'''  [[File:OWASP_Seminar_Flyer-May_2012.pdf]] This is the flyer of Morocco Chapter seminar. A short description of the seminar with the agenda and titles.
+
== OWASP participe à l'évènement MCSC 2017 à l'ENSIAS Rabat ==
<br>
 
  
*'''Events Sponsors :'''
+
= Meetings 2016 =
<strong>Axel Telecom is a Telecom and Network Cabling company in Morcco based in Casablanca</strong>
 
[[File:Axetelecom.jpg|none|300px|caption]]<br>
 
<strong>Vinci SCHOOL is a the first engineering school in Information Technology and Security</strong>
 
[[File:Vinci-rabat.png|none|300px|caption]]<br>
 
<strong>Lexsi Group is an international consulting group specialized in protecting information assets, strongly driven towards innovation</strong>
 
[[File:Lexsi.png|none|300px|caption]]<br>
 
<strong>Fidens est un cabinet de conseil et d’audit, spécialiste de la sécurité des systèmes d’information, indépendant des éditeurs et des constructeurs informatiques</strong>
 
[[File:Fidens.jpg|none|300px|caption]]
 
<br>
 
= Events Sponsors =
 
<strong>Call for additional sponsors</strong>
 
<br>
 
<strong>Axel Telecom is a Telecom and Network Cabling company in Morcco based in Casablanca</strong>
 
[[File:Axetelecom.jpg|none|300px|caption]]<br>
 
<strong>Vinci SCHOOL is a the first engineering school in Information Technology and Security</strong>
 
[[File:Vinci-rabat.png|none|300px|caption]]<br>
 
<strong>Lexsi Group is an international consulting group specialized in protecting information assets, strongly driven towards innovation</strong>
 
[[File:Lexsi.png|none|300px|caption]]<br>
 
<strong>Fidens est un cabinet de conseil et d’audit, spécialiste de la sécurité des systèmes d’information, indépendant des éditeurs et des constructeurs informatiques</strong>
 
[[File:Fidens.jpg|none|300px|caption]]
 
<br>
 
  
= OWASP Moroco Local News  =
+
== OWASP participe à l'évènement MCSC 2016 à l'ENSIAS Rabat/Maroc le 14 et 15 mai 2016 ==
  
2012-05-02&nbsp;: '''VINCI school at Rabat provide as with a large room for our seminars. Thanks to the President of VINCI Mr Amine RACHDI'''
+
J'ai le plaisir que l'OWASP Morocco Chapter participe en tant que partenaire sécurité à l'évènement MCSC 2016 à l'ENSIAS Rabat le week-end du 14 au 15 mai 2015:
  
2010-12-26&nbsp;: INSEC (Information Security Club)is planing on 16th of April 2011 the first edition of "Moroccan Cyber Security Challenge". A challenge that will gather teams from 14 engineering schools in Morocco interested to information security and assurance. OWASP will be present in this events.
+
moroccancybersecuritychallenge.com/mcsc-2016
  
2010-12-24&nbsp;: First meeting preparation in Morocco in Rabat or Casablanca
 
  
2010-12-24&nbsp;: Modification of Morocco Local Chapter Wiki
+
Je vous informe que l'OWASP intervient avec les thèmes suivants:
  
2010-12-24&nbsp;: Azzeddine RAMRAMI is co-leader for Morocco local chapter. Welcome!
+
1. Une conference sur IOT SECURITY avec Mlle.Sanae, PhD Studnet ENSA Tétouan/OWASP Morocco Team
 +
2. Un hands-on de 3h sur comment sécuriser une application web les outils opensource, Azzeddine RAMRAMI, OWASP Leader/IBM Security Senior Architect
  
 +
Les inscriptions sont disponibles via le lien suivant:
  
= OWASP Morocco past meetings  =
+
https://goo.gl/mZuX1E
  
== La sécurité pour le métier de la santé à la Faculté de Médecine de Rabat - Laboratoire de Pharmacologie - 19 Octobre 2011 ==
+
N’hésitez pas donc à s'inscrire et à inviter toute personne intéressée.
  
*'''MAIN PRESENTER:''' Azzeddine RAMRAMI, OWASP Leader<br>
+
Notre sponsor pour cet events est [http://www.adamridson.com ADAM RIDSON]
*'''ABSTRACT:''' Une introduction générale de la sécurité appliquée aux métiers de la santé. Il y  avait plus de 60 participants.
 
  
== Web Application Security Training at INPT (INSTITUT NATIONAL DES POSTES ET DES TELECOMMUNICATION - October 20<sup>th</sup>, 2011 - at  INPT Rabat/Morocco on October 2011  ==
+
http://www.adamridson.com/wp-content/uploads/2015/11/logo.001-1024x400.png
  
*'''MAIN PRESENTER:''' Azzeddine RAMRAMI, OWASP Leader<br>  
+
= Events Sponsors  =
*'''ABSTRACT:''' During this tarining reserved to INPT students Azzeddine RAMRAMI will present a complete Architecture Security Framework to implement Web Application Security the IT landscape. OWASP will be present in this event.
+
<strong>We need your help, Call for additional sponsors</strong>
*'''WHEN: '''October 20th, 2011
+
We need sponsors for meeting room, flight cost, hotel accomodations.
*'''WHERE:''' INPT Rabat/Morocco see&nbsp;[http://www.inpt.ac.ma http://www.inpt.ac.ma]<br>
+
Please contact the Chapter Leader on how to apply.
*'''SPONSORS:''' Welcome to any company. Please contact the Organizer. <br>  
+
<br>
[[File:Axetelecom.jpg]]
 
  
== INSEC (Information Security Club) Challenge - April, 16<sup>th</sup>, 2011 - First edition of "Moroccan Cyber Security Challenge" at ENSIAS Rabat on April 2011 ==
+
= Chapter Meeting =
  
*'''MAIN PRESENTER:''' Yasser ABOUKIR, President of INSEC (Information Security Club)<br>
+
Volonteer are encouraged to join OWASP Morocco Chapter. Please contact the Chapter Leader [mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI]
*'''ABSTRACT:'''INSEC (Information Security Club) is planning, on April 16th 2011, to organize the first edition of "Moroccan Cyber Security Challenge". A challenge that will gather teams from 14 engineering schools in Morocco interested to information security and assurance. OWASP will be present in this event.
+
= OWASP Moroco Local News  =
  
TBD
+
2015-03-14&nbsp;: '''VINCI school at Rabat provide as with a large room for our seminars. Thanks to the President of VINCI Mr Amine RACHDI'''
  
*'''WHEN: '''April 16/17th ,2011
+
2014-06-22&nbsp;: '''MoroccoJUG (Morocco Java User Group) and OWASP Morocco organised a new Java Secure Coding session at Centre Eclipse Casablanca. See http://www.meetup.com/MoroccoJUG/'''
*'''WHERE:''' ENSIAS, RABAT/Morocco  
 
*'''REGISTRATION:'''INSEC (Information Security Club). Registration is mandatory, see&nbsp;[http://www.inseclub.net http://www.inseclub.net] for more information. .
 
*'''SPONSORS:''' The sponsors list should be added soon.<br>
 
*'''PROGRAM:''' [http://www.inseclub.net/ Information Security Club]
 
*'''* A lot of prizes will be offered by sponsors &nbsp; &nbsp; ( Under Construction )'''
 
  
    14:00-14:30 Welcome
+
2012-05-02&nbsp;: '''VINCI school at Rabat provide as with a large room for our seminars. Thanks to the President of VINCI Mr Amine RACHDI'''
14:30-18:30 Keynotes
 
18:30-19:30 Open discussion
 
19:30-...  End of the meeting at the ENSIAS Rabat
 
  
 +
2010-12-26&nbsp;: INSEC (Information Security Club)is planing on 16th of April 2011 the first edition of "Moroccan Cyber Security Challenge". A challenge that will gather teams from 14 engineering schools in Morocco interested to information security and assurance. OWASP will be present in this events.
  
== OWASP Morocco Board Meeting - April 8<sup>th</sup>, 2011 - at 8pm (GMT+2)  ==
+
2010-12-24&nbsp;: First meeting preparation in Morocco in Rabat or Casablanca
  
*'''MAIN PRESENTER''': Azzeddine RAMRAMI
+
2010-12-24&nbsp;: Modification of Morocco Local Chapter Wiki
*'''ABSTRACT''': This is the first meeting for OWASP Morocco Local Chapter
 
  
----
+
2010-12-24&nbsp;: Azzeddine RAMRAMI is co-leader for Morocco local chapter. Welcome!
  
To join the online meeting (Now from mobile devices!)
 
  
----
+
= OWASP Morocco past meetings  =
  
#Go to https://freetrial.webex.com/freetrial/j.php?ED=145387882 &lt;https://freetrial.webex.com/freetrial/j.php?ED=145387882&amp;UID=0&amp;RT=MiMxMzY%3D&gt; &amp;UID=0&amp;RT=MiMxMzY%3D
+
== OWASP Training Day : Web Application Security Course - Secure Coding Techniques - March 28<sup>th</sup>, 2013 - at  Rabat/Morocco ==
#If requested, enter your name and email address.
 
#If a password is required, enter the meeting password: (This meeting does not require a password.)
 
#Click "Join".
 
#Follow the instructions that appear on your screen.<br>
 
  
*'''AGENDA''':<br>
+
*'''MAIN PRESENTERS:''' Azzeddine RAMRAMI: OWASP Leader<br>
 +
*'''ABSTRACT:''' During this training class Azzeddine RAMRAMI and two other OWASP Volunteers will present a Web Application Security and Secure Coding based on Java and PHP Security, .NET Security and Web 2.0 Botnets.<br>
 +
*'''WHEN: '''March 28<sup>th</sup>, 2013
 +
*'''WHERE:''' VINCI Ecole Supérieure Rabat/Morocco see&nbsp;[http://www.vinci.ma/ VINCI Ecole Supérieure Rabat]<br>
 +
''' 10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected]<br>'''
 +
*'''REGISTRATION:'''
 +
'''At AXEL TELECOM ([http://www.axeltelecom.fr/homepage/owasp-training-day Axel Telecom])'''
 +
'''or at VINCI  ([http://www.vinci.ma VINCI Ecole Supérieure])'''
 +
*'''FEES:''' Course is free of charge. Nb of seat limited to 25 per class<br>
 +
*'''SPONSORS:''' Sponsor are welcome to support this event, please contact the Chapter Leader [mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI] <br>
 +
*'''AGENDA:''' OWASP Seminars<br>
 +
*'''-----------------------------------------------'''
 +
*'''Opening Session :''' OWASP Presentation and Introduction - 9:30am to 10am - Seat : No Limit<br>
 +
*'''Session 1:''' Secure Coding Technique - Technical Course - 10am to 5pm - Seat : 25<br>
 +
*'''Session 2:''' Resilient C&C Botnets Using Web 2.0 Technologies - Presentation, PoC and Demo - 10am to 5pm - Seat : 25<br>
 +
*'''Session 3:''' Secure Coding Cryptograhy Crash Course - Theory 10am à 12am - Seat : 25<br>
 +
*'''Session 3:''' Secure Coding Cryptograhy Crash Course - Hands-On 2pm à 5pm - Seat : 25<br>
 +
*'''-----------------------------------------------'''
 +
*'''Optional:''' Please BYOD if you want to participate to PoC, Hands-on and Demo<br>
  
#Presentation of all OWASP Morocco Chapter board membe.
 
#Create a local “Association” with the name of OWASP Morocco Chapter: this will help us to open a banking account , get donation and sponsoring.
 
#Open subjects.<br>
 
  
*'''WHEN''': 08th &amp; 11th April 2011 at 8pm GMT+2
+
== OWASP Training Day : Web Application Security Course - Secure Coding Techniques - March 28<sup>th</sup>, 2013 - at Rabat/Morocco ==
*'''WHERE''': via WebEx
 
*'''REGISTRATION''': Free Access to all interested to OWASP Morocco Local Chapter.
 
  
<br>  
+
*'''MAIN PRESENTERS:''' Azzeddine RAMRAMI: OWASP Leader<br>  
 +
*'''ABSTRACT:''' During this training class Azzeddine RAMRAMI and two other OWASP Volunteers will present a Web Application Security and Secure Coding based on Java and PHP Security, .NET Security and Web 2.0 Botnets.<br>
 +
*'''WHEN: '''March 28<sup>th</sup>, 2013
 +
*'''WHERE:''' VINCI Ecole Supérieure Rabat/Morocco see&nbsp;[http://www.vinci.ma/ VINCI Ecole Supérieure Rabat]<br>
 +
''' 10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected]<br>'''
 +
*'''REGISTRATION:'''
 +
'''At AXEL TELECOM ([http://www.axeltelecom.fr/homepage/owasp-training-day Axel Telecom])'''
 +
'''or at VINCI  ([http://www.vinci.ma VINCI Ecole Supérieure])'''
 +
*'''FEES:''' Course is free of charge. Nb of seat limited to 25 per class<br>
 +
*'''SPONSORS:''' Sponsor are welcome to support this event, please contact the Chapter Leader [mailto:azzeddine.ramrami(at)owasp.org Azzeddine RAMRAMI] <br>
 +
*'''AGENDA:''' OWASP Seminars<br>
 +
*'''-----------------------------------------------'''
 +
*'''Opening Session :''' OWASP Presentation and Introduction - 9:30am to 10am - Seat : No Limit<br>
 +
*'''Session 1:''' Secure Coding Technique - Technical Course - 10am to 5pm - Seat : 25<br>
 +
*'''Session 2:''' Resilient C&C Botnets Using Web 2.0 Technologies - Presentation, PoC and Demo - 10am to 5pm - Seat : 25<br>
 +
*'''Session 3:''' Secure Coding Cryptograhy Crash Course - Theory 10am à 12am - Seat : 25<br>
 +
*'''Session 3:''' Secure Coding Cryptograhy Crash Course - Hands-On 2pm à 5pm - Seat : 25<br>
 +
*'''-----------------------------------------------'''
 +
*'''Optional:''' Please BYOD if you want to participate to PoC, Hands-on and Demo<br>
 +
== Web Application Security Seminar - May 18<sup>th</sup>, 2012 - at  VINCI School Rabat/Morocco ==
  
== OWASP Morocco - On Tuesday October 28, 2011, Azzeddine RAMRAMI made a presentation to the concept of Ethical Hacking at ENSIAS Rabat. ==
+
*'''MAIN PRESENTERS:''' Azzeddine RAMRAMI: OWASP Leader, Hamza WARAKI: Pôle Sécurité PenTest OWASP Morocco, Tarif EL AOUADI from Lexi and Intissar from VINCI<br>
 +
*'''ABSTRACT:''' During this seminars Azzeddine RAMRAMI will present a complete Architecture Security Framework to implement Web Application Security the IT landscape. Hamza WARAKI will present how to conduct an OWASP Web Application PenTesting. OWASP activity and spirit will be presented in this event.
 +
*'''WHEN: '''May 18<sup>th</sup>, 2012
 +
*'''WHERE:''' VINCI Ecole Supérieure Rabat/Morocco see&nbsp;[http://www.vinci.ma/ VINCI Ecole Supérieure Rabat]<br>
 +
''' 10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected].ma<br>'''
  
*This presentation is done for all member of INSEC (INformation Security Club). During this presentation the exchange between the members of the club and Azzeddine RAMRAMI was very interesting and rich.
+
*'''REGISTRATION:'''
 +
'''At AXEL TELECOM ([http://www.axeltelecom.fr/index.php/ressources/seminaire-owsap Axel Telecom])'''
 +
'''or at VINCI  ([http://www.vinci.ma VINCI Ecole Supérieure])'''
 +
*'''PROGRAM:'''
 +
09:00-09:30 Welcome<br>
 +
09:30-09:45 OWASP Presentation ( Azzeddine RAMRAMI )<br>
 +
09:45-10:00 Security Awarnasse ( Tarik EL AOUADI )<br>
 +
10:00-10:30 OSSTMM v3.0 a PenTest Methodlogy - Overview ( Intissar EL MEZROUI )<br>
 +
10:30-10:45 PAUSE<br>
 +
10:45-11:30 How to conduct a Web Application Pen Testing ( Hamza WARRAKI)<br>
 +
11:30-12:00 OWASP WebGoat & Attack Example (A virtual Hacking Environnement)  (Nawfal Makdad )<br>
 +
12:00-14:30 PRIERE DE VENDREDI<br>
 +
14:30-15:30 OWASP WebGoat & Attack Example (A virtual Hacking Environnement)  (Nawfal Makdad )<br>
 +
15:30-16:15 Smartphone Security (Tarik EL OUADI)<br>
 +
16:15-16:30 PAUSE <br>
 +
16:30-17:00 Smartphone Security (Tarik EL AOUADI) <br>
 +
17:00-17:45 Writing Secure Code : Java Principles ( Azzeddine RAMRAMI )<br>
 +
17:45-18:00 Questions & Answers<br>
  
<br> <br>  
+
*'''Event Flyer :'''  [[File:OWASP_Seminar_Flyer-May_2012.pdf]] This is the flyer of Morocco Chapter seminar. A short description of the seminar with the agenda and titles.
 +
<br>  
  
== OWASP Morocco - February 28 to 05 March 2011<sup>th</sup>, Ecole de cryptographie à l'ENS Casablanca et à l'ENSA SAFI on Mars 2011  ==
 
  
*'''MAIN PRESENTER:''' Abdelhak ALAZAHRI , Professeur ENS Casablanca
 
*'''ABSTRACT:''' En partenariat avec l'AMC (l'Association Marocaine de Cryptographie) et l'ENS de Casablanca, l'OWASP Morocco participe à l'Ecole de printemps en cryptographie à l'ENS de Casablanca et l'ENSA de SAFI.
 
*'''WHEN:''' ENS Casablanca &amp; ENSA de Safi
 
*'''WHERE:''' Safi et Casablanca
 
*'''REGISTRATION:''' Participation gratuite sur le site de l'AMC [http://www.amcrypto.org/Root/ http://www.amcrypto.org/Root/]
 
*'''SPONSORS:''' ENS de Casablanca
 
*'''PROGRAM:'''
 
*D. Stehlé&nbsp;: Introduction à la cryptographie reposant sur les réseaux.
 
*F. Laguillaumie&nbsp;: Factorisation d'entiers et Cryptographie.
 
*Abderrahmane Nitaj&nbsp;: Cryptanalyse de RSA, NTRU et Knapsack.
 
*Abdelhak Azhari&nbsp;: Tores algébriques et cryptographie
 
*Azzeddine RAMRAMI&nbsp;: Implémentation des algorithmes modernes en Java: IBE, chiffrement de mails, chiffrement de fichier
 
  
 
= Resources =
 
= Resources =
== Ethical Hacking LiveCD ==
+
== Morocco Cyber Security Event Virtual Machin image==
  
 
To be posted after the first meeting  
 
To be posted after the first meeting  
Line 176: Line 271:
 
== Downloads ==
 
== Downloads ==
 
== Papers and Articles ==
 
== Papers and Articles ==
__NOTOC__ <headertabs />  
+
 
 +
__NOTOC__ <headertabs></headertabs>  
  
 
[[Category:Morocco]]
 
[[Category:Morocco]]

Latest revision as of 12:41, 9 September 2019

AppSec-MA-2018.PNG
Mosquee Hassan II.PNG

Scope of the board is to discuss and approve local activities, meetings and plans.


OWASP Morocco

Welcome to the Morocco chapter homepage. The chapter Leader is
Azzeddine RAMRAMI


Morocco Chapter co-leaders and team member

Tarik EL AOUADI
Alaeddine MESBAHI


Board member of Morocco Chapter
Abdessalem ELJAI
Othmane ERRAJI
LAMIYA Ramrami


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


Contacts et Propositions de Présentations/Contributions

Entreprises, Individuels, Monde Académique, Sponsors, Supports, tout le monde est bienvenu à l'OWASP.

Pour les Entreprises souhaitant adhérer à l'OWASP, le montant de l'adhésion annuelle de $5000 US (dont 40% est reversé au Chapitre de votre choix) est 100% déductible!

Les fonds collectés servent à organiser les meetings du Chapitre Marocain, mais aussi et surtout à construire et organiser avec vous une approche spécifique en fonction de vos souhaits (sessions de sensibilisation, meetings internes, interventions de Speakers, etc.). Tout cela peut être discuté avec le Chapitre Marocain et acté conjointement avec vous si vous souhaitez adhérer à l'OWASP.

N'hésitez pas à nous solliciter si vous souhaitez discuter d'un sujet particulier, ou si vous souhaitez effectuer une présentation lors d'un meeting du Chapitre Marocain.

Amis de la Presse écrite et du Multimédia, n'hésitez pas à faire appel à nous si vous souhaitez notre concours pour vos articles et reportages, vous êtes les bienvenus et nous en serions honorés. Nous avons nous aussi besoin de vous.

Moi et le board du Chapitre Marocain restons modestes dans notre approche, mais nous souhaitons vraiment que le Chapitre OWASP Maroc devienne un de vos contacts de référence.


February 2019 Q1/2019

OWASP Training Day at ONCF, 15th February 2019 in Rabat/Morocco

Azzeddine RAMRAMI will run a one full day developper training on OWASP, on 15th February 2019.

OWASP Morocco Chapter members running this session:

Azzeddine RAMRAMI

Abdessamad TEMMAR

Abdessalam EL JAY

Location: ONCF Club

City: Rabat

Country: Morocco

Course Outline:

  • 1)        Introductions
  • 2)        Agenda
  • 3)        Secure Development Lifecycle (SDLC)
  • 4)        Lab: Threat Modeling
  • 5)        Principles of Secure Code
  • 6)        Authentication & Authorization
  • 7)        Lab: Access Control
  • 8)        Mini-Lab: Weak Session Identifiers
  • 9)        Session Management
  • 10)      Lab: SQL Injection
  • 11)      Lab: Cross-Site Scripting
  • 12)      Input Validation
  • 13)      Lab: SQL Injection Patching
  • 14)      Lab: Cross-Site Scripting Patching
  • 15)      Proper Encryption
  • 16)      Mini-Lab: Hash Breaking
  • 17)      Logic Flaws
  • 18)      Lab: Logic Flaw Exploitation
  • Addition Labs:
  • 19)      Other Attacks
  • 20)      Mini-Lab: XML Attacks
  • 21)      Security Hygiene
  • 22)      Final Lab: Hacking Contest

Sponsor of this event: MUNISYS (http://www.munisys.net.ma/)

June 2019 Q2/2019

OWASP Training Day at Mohammed VI Polytechnic University on June 27th, 2019 in Ben Guerir Marrakech/Morocco

Azzeddine RAMRAMI with OWASP Morocco Team will run one full day developper training on workshop OWASP, on 27th June 2019.

This session will run by Azzeddine RAMRAMI, Abdessalam ELJAI and Othmane TAGAMART.

Location: Universite Mohamed VI Bengruir

City: Ben Guerir / UM6P

AdresseMohammed VI Polytechnic University 

Lot 660, Hay Moulay Rachid Ben Guerir, 43150, Morocco

Country: Morocco

Workshop Outline: Two sessions

  • Introduction à l'OWASP: Abdessalam JAY                                                                                                                09h00 - 09h30 
  • L'état de l'art de la sécurité IoT: Othmane TAMAGARTI                                                                                            09h30 - 10h30  
  • Pause café                                                                                                                                                                 10h30 - 11h00 
  • Secure Coding Java & .NET with OWASP TOP 10 2017 Part 1: Azzeddine RAMRAMI & Othmane TAMAGART   11h00 - 13h00 
  • Pause déjeuner                                                                                                                                                          13h00 - 14h00 
  • Secure Coding Java & .NET with OWASP TOP 10 2017 Part 2: Azzeddine RAMRAMI & Othmane TAMAGART   14h00 - 16h00   
  • Pause café                                                                                                                                                                 16h00 - 16h30 
  • Secure Coding Java & .NET with OWASP TOP 10 2017 Part 3: Azzeddine RAMRAMI & Othmane TAMAGART   16h30 - 18h00  

Contact to subscription:
Azzeddine RAMRAMI
https://www.owasp.org/index.php/Morocco#tab=Meetings_2019

Sponsor of this event: Adam Ridson

Welcome to the second edition of OWASP AppSec Morocco and Africa in Casablanca, Hotel Val d'Anfa on November 15-16, 2018.

https://2018.appsecmorocco.org/agenda/

At AppSec Morocco & Africa you can connect with over 250 security professionals in our sponsor hall. Our floor plan is designed to allow you to engage with speakers and attendees.

Thank you to the Sponsors of Appsec Morocco & Africa 2018 :

https://2018.appsecmorocco.org/sponsors/

Here the final list of our speakers from differents countries including Africa (Morocco and Algerie), Canada, Europe and Asia.

https://2018.appsecmorocco.org/speakers/

OWASP AppSec Africa 2017

OWASP participe à l'évènement MCSC 2017 à l'ENSIAS Rabat

OWASP participe à l'évènement MCSC 2016 à l'ENSIAS Rabat/Maroc le 14 et 15 mai 2016

J'ai le plaisir que l'OWASP Morocco Chapter participe en tant que partenaire sécurité à l'évènement MCSC 2016 à l'ENSIAS Rabat le week-end du 14 au 15 mai 2015:

moroccancybersecuritychallenge.com/mcsc-2016


Je vous informe que l'OWASP intervient avec les thèmes suivants:

1. Une conference sur IOT SECURITY avec Mlle.Sanae, PhD Studnet ENSA Tétouan/OWASP Morocco Team 2. Un hands-on de 3h sur comment sécuriser une application web les outils opensource, Azzeddine RAMRAMI, OWASP Leader/IBM Security Senior Architect

Les inscriptions sont disponibles via le lien suivant:

https://goo.gl/mZuX1E

N’hésitez pas donc à s'inscrire et à inviter toute personne intéressée.

Notre sponsor pour cet events est ADAM RIDSON

logo.001-1024x400.png

We need your help, Call for additional sponsors We need sponsors for meeting room, flight cost, hotel accomodations. Please contact the Chapter Leader on how to apply.

Volonteer are encouraged to join OWASP Morocco Chapter. Please contact the Chapter Leader Azzeddine RAMRAMI

2015-03-14 : VINCI school at Rabat provide as with a large room for our seminars. Thanks to the President of VINCI Mr Amine RACHDI

2014-06-22 : MoroccoJUG (Morocco Java User Group) and OWASP Morocco organised a new Java Secure Coding session at Centre Eclipse Casablanca. See http://www.meetup.com/MoroccoJUG/

2012-05-02 : VINCI school at Rabat provide as with a large room for our seminars. Thanks to the President of VINCI Mr Amine RACHDI

2010-12-26 : INSEC (Information Security Club)is planing on 16th of April 2011 the first edition of "Moroccan Cyber Security Challenge". A challenge that will gather teams from 14 engineering schools in Morocco interested to information security and assurance. OWASP will be present in this events.

2010-12-24 : First meeting preparation in Morocco in Rabat or Casablanca

2010-12-24 : Modification of Morocco Local Chapter Wiki

2010-12-24 : Azzeddine RAMRAMI is co-leader for Morocco local chapter. Welcome!


OWASP Training Day : Web Application Security Course - Secure Coding Techniques - March 28th, 2013 - at Rabat/Morocco

  • MAIN PRESENTERS: Azzeddine RAMRAMI: OWASP Leader
  • ABSTRACT: During this training class Azzeddine RAMRAMI and two other OWASP Volunteers will present a Web Application Security and Secure Coding based on Java and PHP Security, .NET Security and Web 2.0 Botnets.
  • WHEN: March 28th, 2013
  • WHERE: VINCI Ecole Supérieure Rabat/Morocco see VINCI Ecole Supérieure Rabat

10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected]

  • REGISTRATION:

At AXEL TELECOM (Axel Telecom) or at VINCI (VINCI Ecole Supérieure)

  • FEES: Course is free of charge. Nb of seat limited to 25 per class
  • SPONSORS: Sponsor are welcome to support this event, please contact the Chapter Leader Azzeddine RAMRAMI
  • AGENDA: OWASP Seminars
  • -----------------------------------------------
  • Opening Session : OWASP Presentation and Introduction - 9:30am to 10am - Seat : No Limit
  • Session 1: Secure Coding Technique - Technical Course - 10am to 5pm - Seat : 25
  • Session 2: Resilient C&C Botnets Using Web 2.0 Technologies - Presentation, PoC and Demo - 10am to 5pm - Seat : 25
  • Session 3: Secure Coding Cryptograhy Crash Course - Theory 10am à 12am - Seat : 25
  • Session 3: Secure Coding Cryptograhy Crash Course - Hands-On 2pm à 5pm - Seat : 25
  • -----------------------------------------------
  • Optional: Please BYOD if you want to participate to PoC, Hands-on and Demo


OWASP Training Day : Web Application Security Course - Secure Coding Techniques - March 28th, 2013 - at Rabat/Morocco

  • MAIN PRESENTERS: Azzeddine RAMRAMI: OWASP Leader
  • ABSTRACT: During this training class Azzeddine RAMRAMI and two other OWASP Volunteers will present a Web Application Security and Secure Coding based on Java and PHP Security, .NET Security and Web 2.0 Botnets.
  • WHEN: March 28th, 2013
  • WHERE: VINCI Ecole Supérieure Rabat/Morocco see VINCI Ecole Supérieure Rabat

10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected]

  • REGISTRATION:

At AXEL TELECOM (Axel Telecom) or at VINCI (VINCI Ecole Supérieure)

  • FEES: Course is free of charge. Nb of seat limited to 25 per class
  • SPONSORS: Sponsor are welcome to support this event, please contact the Chapter Leader Azzeddine RAMRAMI
  • AGENDA: OWASP Seminars
  • -----------------------------------------------
  • Opening Session : OWASP Presentation and Introduction - 9:30am to 10am - Seat : No Limit
  • Session 1: Secure Coding Technique - Technical Course - 10am to 5pm - Seat : 25
  • Session 2: Resilient C&C Botnets Using Web 2.0 Technologies - Presentation, PoC and Demo - 10am to 5pm - Seat : 25
  • Session 3: Secure Coding Cryptograhy Crash Course - Theory 10am à 12am - Seat : 25
  • Session 3: Secure Coding Cryptograhy Crash Course - Hands-On 2pm à 5pm - Seat : 25
  • -----------------------------------------------
  • Optional: Please BYOD if you want to participate to PoC, Hands-on and Demo

Web Application Security Seminar - May 18th, 2012 - at VINCI School Rabat/Morocco

  • MAIN PRESENTERS: Azzeddine RAMRAMI: OWASP Leader, Hamza WARAKI: Pôle Sécurité PenTest OWASP Morocco, Tarif EL AOUADI from Lexi and Intissar from VINCI
  • ABSTRACT: During this seminars Azzeddine RAMRAMI will present a complete Architecture Security Framework to implement Web Application Security the IT landscape. Hamza WARAKI will present how to conduct an OWASP Web Application PenTesting. OWASP activity and spirit will be presented in this event.
  • WHEN: May 18th, 2012
  • WHERE: VINCI Ecole Supérieure Rabat/Morocco see VINCI Ecole Supérieure Rabat

10,Rue Al Yamama (Aproximité de la gare Rabat-Ville), Rabat - Tél: 05 37 70 69 05 - E-mail: [email protected]

  • REGISTRATION:

At AXEL TELECOM (Axel Telecom) or at VINCI (VINCI Ecole Supérieure)

  • PROGRAM:

09:00-09:30 Welcome
09:30-09:45 OWASP Presentation ( Azzeddine RAMRAMI )
09:45-10:00 Security Awarnasse ( Tarik EL AOUADI )
10:00-10:30 OSSTMM v3.0 a PenTest Methodlogy - Overview ( Intissar EL MEZROUI )
10:30-10:45 PAUSE
10:45-11:30 How to conduct a Web Application Pen Testing ( Hamza WARRAKI)
11:30-12:00 OWASP WebGoat & Attack Example (A virtual Hacking Environnement) (Nawfal Makdad )
12:00-14:30 PRIERE DE VENDREDI
14:30-15:30 OWASP WebGoat & Attack Example (A virtual Hacking Environnement) (Nawfal Makdad )
15:30-16:15 Smartphone Security (Tarik EL OUADI)
16:15-16:30 PAUSE
16:30-17:00 Smartphone Security (Tarik EL AOUADI)
17:00-17:45 Writing Secure Code : Java Principles ( Azzeddine RAMRAMI )
17:45-18:00 Questions & Answers



Morocco Cyber Security Event Virtual Machin image

To be posted after the first meeting

Downloads

Papers and Articles