This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Denver"

From OWASP
Jump to: navigation, search
m
m (Chapter Board of Directors: SB added Brad Gable)
 
(57 intermediate revisions by 7 users not shown)
Line 1: Line 1:
{{Chapter Template|chaptername=Denver|extra=Chapter leader is Steve Kosten.   |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-denver|emailarchives=http://lists.owasp.org/pipermail/owasp-denver}}
+
{{Chapter Template|chaptername=Denver|extra=Our chapter president is Serge Borso.<br/>
 +
<!--<i>Don't let the dated look and feel of this website fool you...</i> <br /> -->
 +
<b><span style="font-size:152%; line-height: 2em;">The Denver OWASP Chapter is one of the largest and most active in the World!</span></b><br/>
 +
<!--<b><span style="font-size:152%; line-height: 2em; color:#008000">Right now we are working diligently on our annual Front Range OWASP Conference: [https://snowfroc.com SnowFROC]</span></b><br/> -->
 +
Note that we primary use our [http://www.meetup.com/Denver-OWASP/ MeetUp.com] site for regular updates and meeting information so be sure to visit it to keep apprised of our regular meetups.
 +
<br />
 +
<b><span style="font-size:152%; line-height: 2em;">We also organize Denver's premier application security conference [https://snowfroc.com SnowFROC] </span></b> |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-denver|emailarchives=http://lists.owasp.org/pipermail/owasp-denver}}
  
== Local News ==
+
<!-- <b>Meeting details can be found on our [http://www.meetup.com/Denver-OWASP/ MeetUp.com] site.</b>  |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-denver|emailarchives=http://lists.owasp.org/pipermail/owasp-denver}} -->== Sponsorship ==
 +
We can't do what we do alone, its takes a concerted effort and generous sponsors. If you or your company is interested in sponsoring an upcoming chapter meeting or event, please reach out to Serge Borso: serge 'dot' borso 'at' owasp.org. The OWASP foundation, as well as the Denver chapter, is a 501(c)(3) non-profit organization; '''your sponsorship is not only greatly appreciated but is considered a tax deductible donation'''.
  
===Next Chapter Meeting: October 17th at Hosting.com [http://dowasp201210.eventbrite.com/    RSVP Now!!! ] ===
+
== About the chapter ==
 +
The Denver OWASP chapter is comprised of Denver metro area (and beyond) professionals and is constantly evolving. In the early years, our chapter meetups consisted of <b>3-5</b> people talking about appsec in a donated meeting space. From there we have migrated to holding meetings of <b>15-25</b> people at the Hosting.com building in Denver, to <b>30-40</b> people on the Community College of Aurora campus, to maxing out capacity at the Chinook Tavern as well as Dave & Busters (on many nights). The Denver OWASP chapter is focused on our security community, and discussing advances in technology that impact us all.  
  
Pizza and Chapter Business starting at 6, presentation starting at about 6:30...
+
<br />Chapter Meetings are held the 3rd Wednesday of designated months, see the [http://www.meetup.com/Denver-OWASP/ MeetUp.com] site for regular updates and meeting information. <br />
  
[http://dowasp201210.eventbrite.com/ RSVP here]
+
A large part of why 100+ people regularly attend our meetings is due to our presenters (spectacular networking with intelligent individuals coupled with great food and drinks certainly helps). As such, we are always looking for talented speakers ready to share interesting information on a wide variety of topics: Please reach out to Denver OWASP President Serge Borso: serge 'dot' borso 'at' owasp.org if you are interested in presenting at one of our regular meetups.
  
'''Topic: DevOps: The Answer App Security didn't know we needed'''
+
==Submit your presentation==
 +
If you are interested in presenting at a regular chapter meeting please submit the following information to serge 'dot' borso 'at' owasp.org: Presentation Title, Presentation Abstract and Speaker(s) BIO. The Information Security field is very broad and essentially any information security topic is welcome including: New and exciting research, presentations on appsec, breaches, crypto, WIFI, cloud, emerging technology/trends, etc.
  
Is security still an afterthought in your SDLC?  Is "the" security practitioner in your SDLC a pariah?  Are you ready for that to change?  Raf will share some insight that might help YOU and YOUR team FINALLY integrate security into your SDLC...
+
<!--
 +
===THANK YOU TO OUR SPONSORS===
 +
[[File:SolutionsIILogo.jpg]]
  
'''About Raf:''' Rafal Los, Chief Security Evangelist for Hewlett-Packard Software, combines nearly 15 years of subject-matter expertise in information security with a critical business risk management perspective. From technical research to building and implementing enterprise application security programs, Rafal has a track record with organizations of diverse sizes and verticals.  He is a featured speaker at events around the globe, and has presented at events produced by OWASP, ISSA, Black Hat,  and SANS among many others. He stays active in the community by writing, speaking and contributing research, representing HP in OWASP, the Cloud Security Alliance and other industry groups. His blog, Following the White Rabbit, with his unique perspective on security and risk management has amassed a following from his industry peers, business professionals, and even the media and can be found at
+
A big thank you to [http://solutions-ii.com/ Solutions II] for being our primary monthly meeting sponsor (ongoing now for several years)!! It is much appreciated!
  
http://hp.com/go/white-rabbit.
 
 
Prior to joining HP, Los defined what became the software security program and served as a regional security lead at a Global Fortune 100 contributing to the global organization’s security and risk-management strategy internally and externally.  Rafal prides himself on being able to add a ‘tint of corporate realism’ to information security.
 
 
Rafal received his B. S. in Computer Information Systems from Concordia University, River Forest, Ill.
 
 
* Twitter:@Wh1t3Rabbit
 
* Speaker URL:hp.com/go/white-rabbit
 
* Facebook:facebook.com/Wh1t3RabbitPage
 
 
'''About the chapter:'''
 
Chapter Meetings are held the 3rd Wednesday of designated months for the Denver Chapter, and the 3rd Thursday of designated months for the [[Boulder|Boulder]] Chapter.  If you have an idea for a topic or speaker or would like to present, please
 
reach out to Andy Lewis, Denver OWASP Chapter Leader: alewis 'at' owasp.org
 
 
<!-- June 20th at 6'ish at Hosting.  [http://www.eventbrite.com/org/371792456    RSVP HERE ] so we can order the right # of pizzas -->
 
 
'''Thanks to [http://www.hosting.com/ Hosting.com] for... hosting us, and thanks to [http://www.hpenterprisesecurity.com HP] for providing a speaker and dinner for October's meeting...'''
 
 
 
Future meetings are planned for: stay tuned for 2013.
 
  
 +
Solutions II is nationally recognized for world class innovation in virtualization, business continuance, data lifecycle management and information security, networking and compliance. Solutions II’s security practice specializes in risk and compliance, including mobile device management, SIEM, Next Generation Firewalls, IDS/IPS, encryption and more. Solutions II assists clients every day to leverage technologies and services that drive the cost out of IT. Solutions II's commitment to success includes a professional services practice dedicated to increasing customer service levels and decreasing the time and support required for implementations to keep their Clients "Performing Ahead of the Curve.”.
 +
-->
 +
<!-- All chapter meetings will be announced via email to those who sign up for Denver OWASP from this page and also at our [http://www.meetup.com/Denver-OWASP/ : Denver OWASP Meetup location]
 +
'''Thanks to [http://solutions-ii.com/ Solutions II] for providing food and drinks for our meetings...''' -->
 
==Chapter Board of Directors==
 
==Chapter Board of Directors==
 
Here's the team that's putting it all together:
 
Here's the team that's putting it all together:
* Chairman/Chapter Leader - Steve Kosten
+
* Chapter President:  [https://www.linkedin.com/in/sergeborso Serge Borso]
* Director of Communications - Craig Klosterman
+
* Board Member:  [https://www.linkedin.com/in/aaron-cure Aaron Cure]
* Comm Vice-Director - Alan Darien
+
* Board Member: [https://www.linkedin.com/in/bradgable/ Brad Gable]
* Outreach & Education Chair - James Synovec
+
* Board Member:  [https://www.linkedin.com/in/stevekosten Steve Kosten]
* Outreach & Education Vice Chair - Brad Carvalho
+
* Board Member:  [https://www.linkedin.com/in/matt-shufeldt-283677 Matt Shufeldt]
* FROC Chair - Micah Tapman
+
* Board Member:  [https://www.linkedin.com/in/frank-vianzon Frank Vianzon]
* FROC Chair Emeritus - Kathy Thaxton
+
 
  
 +
<!--
 
NOTE: PLEASE CONSIDER FOLLOWING US AT @OWASP303 ON TWITTER AND/OR [http://lists.owasp.org/mailman/listinfo/owasp-denver SUBSCRIBE TO THE MAILING LIST] AND/OR join the OWASP Denver Linked In group.
 
NOTE: PLEASE CONSIDER FOLLOWING US AT @OWASP303 ON TWITTER AND/OR [http://lists.owasp.org/mailman/listinfo/owasp-denver SUBSCRIBE TO THE MAILING LIST] AND/OR join the OWASP Denver Linked In group.
 
+
=====Missed the con?=====
<!-- =====Missed the con?=====
 
 
* [http://www.reddit.com/r/netsec/comments/fgetw/shmoocon_2011_video_collection/ Vids from Schmoocon 2011]
 
* [http://www.reddit.com/r/netsec/comments/fgetw/shmoocon_2011_video_collection/ Vids from Schmoocon 2011]
 
* [http://media.ccc.de/browse/congress/2010/index.html Vids from 27c3]
 
* [http://media.ccc.de/browse/congress/2010/index.html Vids from 27c3]
Line 59: Line 54:
  
 
<!-- =====Wassup Boulder=====
 
<!-- =====Wassup Boulder=====
Boulder is in the process of putting together new leadership.  We hope to share some resources and communication with the Boulder chapter.  If you're interested in working with the Boulder chapter please let us know!  More to come...
+
Boulder has built a strong chapter over the past 3 years.  Any individuals up north of Denver have a great resource.  We hope to share some resources and communication with the Boulder chapter.  If you're interested in meeting with the Boulder chapter please let us know!   
-->
+
 
  
 
<paypal>Denver</paypal>
 
<paypal>Denver</paypal>
 
<hr>
 
<hr>
 +
-->
 +
== Questions, Comments ==
 +
Questions can be directed to
 +
 +
*Serge Borso, Denver OWASP: serge 'dot' borso 'at' owasp.org
 +
 +
<hr />
 +
 +
<!--
 +
==== Chapter Meetings ====
 +
Meetings are usually the 3rd Wednesday of every other month.  If you can't make the Denver meeting, the [[Boulder|Boulder]] meeting is usually the 3rd Thursday of the month.
 +
 +
-->
  
==Questions, Comments==
+
== Past Meetings ==
Questions can be directed to
+
As you can tell we have been doing this for quite some time with regularity. Some of our older presentations are listed below<br /><br />
 +
'''All meetings after July 2014 may be found on our [http://www.meetup.com/Denver-OWASP/ : Denver OWASP Meetup Site]'''
  
*Steve Kosten, Denver OWASP: steve 'dot' kosten 'at' owasp.org
+
[[July 2014:Andy Earle: "Static Analysis: Beyond the Basics"]]
  
<hr>
+
[[March 2014:Matt Shufeldt: "Data Breaches"]]
  
 +
[[Denver_July_2013|July 2013: Jim Manico: "Secure Coding Techniques Part 2"]]
  
==== Chapter Meetings ====
+
[[Denver_June_2013|June 2013: Aaron Cure: "Less Frequently talked about vulnerabilities"]]
Meetings are usually the 3rd Wednesday of the month.  We are trying to have at least 2/quarter.  If you can't make the Denver meeting, the [[Boulder|Boulder]] meeting is usually the 3rd Thursday of the month.
 
  
== Future Meetings ==
+
[[Denver_April_2013|April 2013: Matt Schufeldt: "Security in the SDLC"]]
  
Meetings are planned for the 3rd Wednesdays of September and October.  We may do a social event or two also...
+
[[Denver_March_2013|March 2013: Jim Manico: "Secure Coding Techniques"]]
  
 +
[[Denver_February_2013|February 2013: Chris Roberts: "The Evolution of Hacking"]]
  
<!-- 5 May 2011: SnowFROC 2011 followed by B-Sides "SkiSides".  Details TBD -->
+
[[Denver_January_2013|July 2013: Dave Ferguson: "Building a Successful Application Security Program"]]
  
== Past Meetings ==
+
[[Denver_June_2012|June 2012: Laz: Emerging Threats]]
[[Denver_June_2012|Laz: Emerging Threats]]
 
  
[[Denver May 2012 meeting|Steve Kosten: XSS hands-on]]
+
[[Denver May 2012 meeting|May 2012: Steve Kosten: XSS hands-on]]
  
 
[[Denver April 2012 meeting|April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"]]
 
[[Denver April 2012 meeting|April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"]]
 
[[Denver February 2012 meeting|February 15th 2012: Andy Lewis "Why OWASP? OWASP is the wheel. You don't need to reinvent it!]]
 
  
 
Denver January 2012 meeting January 18th, 2012| Greg Knaddison [http://2011.badcamp.net/program/sessions/how-does-drupal-security-stack "How Does Drupal Security Stack up?"]
 
Denver January 2012 meeting January 18th, 2012| Greg Knaddison [http://2011.badcamp.net/program/sessions/how-does-drupal-security-stack "How Does Drupal Security Stack up?"]
Line 142: Line 149:
 
[[Denver November 2006 meeting|November 2006]]
 
[[Denver November 2006 meeting|November 2006]]
  
 +
<!-- [[November 2013:Joe Gerber: "HTML 5 Geolocation"]]-->
 +
<!-- [[September 2013: Bill Jackson: "Secure Coding Mechanics"]]-->
 +
<!-- [[Denver February 2012 meeting|February 15th 2012: Andy Lewis "Why OWASP? OWASP is the wheel. You don't need to reinvent it!]] -->
 +
<!-- [[Denver January 2015:Serge Borso: "Locking down your webapp...Empowering you application to defend itself"]] -->
 
==[[Related_Organizations|Local Organizations of Interest]]==
 
==[[Related_Organizations|Local Organizations of Interest]]==
  
Line 147: Line 158:
 
Join the [http://lists.owasp.org/mailman/listinfo/owasp-denver OWASP Denver Mailing List] to receive meeting notifications via email
 
Join the [http://lists.owasp.org/mailman/listinfo/owasp-denver OWASP Denver Mailing List] to receive meeting notifications via email
  
 +
<!--
 
==== Twitter Feed @owasp303 ====
 
==== Twitter Feed @owasp303 ====
 
Denver OWASP has created a [http://twitter.com/owasp303 Twitter feed @owasp303] to keep you in the loop.  Whilst the mailing list is primarily intended to be low-traffic and only provide updates regarding the times, locations, and topics for chapter meetings, the Twitter feed will also provide noteworthy appsec updates.
 
Denver OWASP has created a [http://twitter.com/owasp303 Twitter feed @owasp303] to keep you in the loop.  Whilst the mailing list is primarily intended to be low-traffic and only provide updates regarding the times, locations, and topics for chapter meetings, the Twitter feed will also provide noteworthy appsec updates.
Line 159: Line 171:
 
| style="width: 110px; font-size: 95%; color: rgb(0, 0, 0);" |  
 
| style="width: 110px; font-size: 95%; color: rgb(0, 0, 0);" |  
 
|}
 
|}
 
+
-->
 
 
 
 
====Resources====
 
 
 
=====Denver OWASP Chapter Leaders=====
 
*Andy Lewis, Denver OWASP: alewis 'at' owasp.org
 
  
 
=====Key OWASP Resources=====
 
=====Key OWASP Resources=====
Line 171: Line 177:
 
* http://www.owasp.org/images/3/31/ESAPI_One_Page_Handout.pdf
 
* http://www.owasp.org/images/3/31/ESAPI_One_Page_Handout.pdf
 
* http://www.owasp.org/images/a/a1/Legal_One_Page_Handout.pdf
 
* http://www.owasp.org/images/a/a1/Legal_One_Page_Handout.pdf
*
 
 
* http://www.owasp.org/images/a/a3/How_ESAPI_Works.pdf
 
* http://www.owasp.org/images/a/a3/How_ESAPI_Works.pdf
 
* http://www.owasp.org/images/a/ac/LAMP_Should_be_Spelled_LAMPE.pdf
 
* http://www.owasp.org/images/a/ac/LAMP_Should_be_Spelled_LAMPE.pdf
 
* http://www.owasp.org/images/0/01/Getting_started_designing_for_a_level_of_assurance.pdf
 
* http://www.owasp.org/images/0/01/Getting_started_designing_for_a_level_of_assurance.pdf
*
 
 
* http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories
 
* http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories
 
* http://www.owasp.org/index.php/Man_vs._Code
 
* http://www.owasp.org/index.php/Man_vs._Code
*
 
 
* http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf
 
* http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf
*
 
 
* http://www.owasp.org/images/c/cd/PHP-ESAPI_1.0a_install.pdf
 
* http://www.owasp.org/images/c/cd/PHP-ESAPI_1.0a_install.pdf
 
* http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf
 
* http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf
Line 188: Line 190:
 
[[Chapter SOPs|Denver OWASP Chapter SOPs]]
 
[[Chapter SOPs|Denver OWASP Chapter SOPs]]
  
[[FROC Schedule Draft|SnowFROC 2012 Schedule Draft]]
 
 
__NOTOC__
 
__NOTOC__
<headertabs/>
+
<headertabs />
 
[[Category:OWASP Chapter]]
 
[[Category:OWASP Chapter]]
 +
[[Category:United_States]]
 
[[Category:Colorado]]
 
[[Category:Colorado]]

Latest revision as of 19:51, 11 November 2019

OWASP Denver

Welcome to the Denver chapter homepage. Our chapter president is Serge Borso.
The Denver OWASP Chapter is one of the largest and most active in the World!
Note that we primary use our MeetUp.com site for regular updates and meeting information so be sure to visit it to keep apprised of our regular meetups.
We also organize Denver's premier application security conference SnowFROC


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


Sponsorship

We can't do what we do alone, its takes a concerted effort and generous sponsors. If you or your company is interested in sponsoring an upcoming chapter meeting or event, please reach out to Serge Borso: serge 'dot' borso 'at' owasp.org. The OWASP foundation, as well as the Denver chapter, is a 501(c)(3) non-profit organization; your sponsorship is not only greatly appreciated but is considered a tax deductible donation.

About the chapter

The Denver OWASP chapter is comprised of Denver metro area (and beyond) professionals and is constantly evolving. In the early years, our chapter meetups consisted of 3-5 people talking about appsec in a donated meeting space. From there we have migrated to holding meetings of 15-25 people at the Hosting.com building in Denver, to 30-40 people on the Community College of Aurora campus, to maxing out capacity at the Chinook Tavern as well as Dave & Busters (on many nights). The Denver OWASP chapter is focused on our security community, and discussing advances in technology that impact us all.


Chapter Meetings are held the 3rd Wednesday of designated months, see the MeetUp.com site for regular updates and meeting information.

A large part of why 100+ people regularly attend our meetings is due to our presenters (spectacular networking with intelligent individuals coupled with great food and drinks certainly helps). As such, we are always looking for talented speakers ready to share interesting information on a wide variety of topics: Please reach out to Denver OWASP President Serge Borso: serge 'dot' borso 'at' owasp.org if you are interested in presenting at one of our regular meetups.

Submit your presentation

If you are interested in presenting at a regular chapter meeting please submit the following information to serge 'dot' borso 'at' owasp.org: Presentation Title, Presentation Abstract and Speaker(s) BIO. The Information Security field is very broad and essentially any information security topic is welcome including: New and exciting research, presentations on appsec, breaches, crypto, WIFI, cloud, emerging technology/trends, etc.

Chapter Board of Directors

Here's the team that's putting it all together:


OWASP Podcast

OWASP Podcast


Questions, Comments

Questions can be directed to

  • Serge Borso, Denver OWASP: serge 'dot' borso 'at' owasp.org


Past Meetings

As you can tell we have been doing this for quite some time with regularity. Some of our older presentations are listed below

All meetings after July 2014 may be found on our : Denver OWASP Meetup Site

July 2014:Andy Earle: "Static Analysis: Beyond the Basics"

March 2014:Matt Shufeldt: "Data Breaches"

July 2013: Jim Manico: "Secure Coding Techniques Part 2"

June 2013: Aaron Cure: "Less Frequently talked about vulnerabilities"

April 2013: Matt Schufeldt: "Security in the SDLC"

March 2013: Jim Manico: "Secure Coding Techniques"

February 2013: Chris Roberts: "The Evolution of Hacking"

July 2013: Dave Ferguson: "Building a Successful Application Security Program"

June 2012: Laz: Emerging Threats

May 2012: Steve Kosten: XSS hands-on

April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"

Denver January 2012 meeting January 18th, 2012| Greg Knaddison "How Does Drupal Security Stack up?"

September 14th 2011: Chris Schmidt "OWASP ESAPI"

March 17th 2011: Hands on "Hack a Thon"

September 22nd 2010: Eric Duprey: Application Vulnerability Shooting Gallery

August 18th 2010: Clint Pollock: Protecting Your Applications from Backdoors

June 2nd 2010: Front Range OWASP Conference

January 20th 2010: John Evans: Securing Webapps: An Illustrative Overview

November 18th 2009: Anton Rager: Advanced XSS

August 27th 2009: Jon Rose: Security in the Clouds

May 2009: Dr. Joseph McComb & and Daniel Weiske: Compliance and application security testing

March 2009: Front Range OWASP Conference (SnowFROC)

January 2009: David Campbell & Eric Duprey: Guided Tour: AppSec NYC '08 CTF

October 2008: Alex Smolen: The OWASP ASP .NET ESAPI

September 2008: John Dickson: Black Box vs. White Box: Different App Testing Strategies

August 2008: Dan Cornell: Static Analysis

July 2008: David Byrne & Eric Duprey: Grendel-Scan

June 2008: Front Range OWASP Conference: Jeremiah Grossman, Robert Hansen, and more!

May 2008: David Campbell & Eric Duprey: XSS Attacks & Defenses

April 2008: Ryan Barnett: Virtual Patching with ModSecurity

February 2008: Michael Sutton: SQL Injection Revisited

June 2007

April 2007

February 2007

January 2007

November 2006

Local Organizations of Interest

Mailing List

Join the OWASP Denver Mailing List to receive meeting notifications via email


Key OWASP Resources
Chapter Management Links

Denver OWASP Chapter SOPs