Difference between revisions of "OWASP EU Summit 2008 work in progress"
From OWASP
(→EVENT AGENDA) |
(→EVENT AGENDA) |
||
| (36 intermediate revisions by the same user not shown) | |||
| Line 7: | Line 7: | ||
| colspan="4" style="width:90%; background:#C2C2C2" align="center" | Lunch | | colspan="4" style="width:90%; background:#C2C2C2" align="center" | Lunch | ||
|- | |- | ||
| − | | | + | | style="width:10%; background:white" align="center"| |
| + | | colspan="4" style="width:90%; background:white" align="center" | Training Sessions | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center"| 15:00 - 17:00 | | style="width:10%; background:#7B8ABD" align="center"| 15:00 - 17:00 | ||
| − | | style="width:30%; background:# | + | | style="width:30%; background:#c0a0a0" align="center" | Securing WebGoat with ModSecurity<br>Stephen Craig Evans |
| − | | style="width:30%; background:# | + | | style="width:30%; background:#c0a0a0" align="center" | WebSec Apps for Managers and Executives<br>Mano Paul |
| − | | style="width:30%; background:# | + | | style="width:30%; background:#c0a0a0" align="center" | OWASP Testing Guide<br>Matteo Meucci |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 19:00 | | style="width:10%; background:#7B8ABD" align="center" | 19:00 | ||
| − | | colspan="4" style="width:90%; background:# | + | | colspan="4" style="width:90%; background:#F2F2F2" align="center" | Summit Briefing<br>Dinis Cruz and Summit Organization Team |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 20:00 | | style="width:10%; background:#7B8ABD" align="center" | 20:00 | ||
| − | | colspan="4" style="width:90%; background:# | + | | colspan="4" style="width:90%; background:#C2C2C2" align="center" | Dinner |
|- | |- | ||
|} | |} | ||
| Line 27: | Line 28: | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 08:00 | | style="width:10%; background:#7B8ABD" align="center" | 08:00 | ||
| − | | colspan="4" style="width:80%; background:# | + | | colspan="4" style="width:80%; background:#C2C2C2" align="center" | Registration |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center"| 09:00 | | style="width:10%; background:#7B8ABD" align="center"| 09:00 | ||
| − | | colspan="4" style="width:80%; background:# | + | | colspan="4" style="width:80%; background:#F2F2F2" align="center" | Summit Keynote<br>Dinis Cruz and Summit Organization Team |
|- | |- | ||
| − | | style="width:10%; background:#7B8ABD" | | + | | style="width:10%; background:#7B8ABD" align="center" | |
| − | | colspan="2" style="width:45%; background:# | + | | colspan="2" style="width:45%; background:#FFDF80" align="center" | '''Documents''' |
| − | | colspan="2" style="width:45%; background:# | + | | colspan="2" style="width:45%; background:#a0c0e0" align="center" | '''Tools''' |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 09:30 | | style="background:#7B8ABD" align="center" | 09:30 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Testing Guide<br>Matteo Meucci |
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#a0c0e0" align="center" | OWASP JSP Testing Tool<br>Jason Li |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 09:45 | | style="background:#7B8ABD" align="center" | 09:45 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | [https://www.owasp.org/index.php/Image:Code_Review_Eoin.pptx OWASP Code Review Guide]<br>Eoin Keary |
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#a0c0e0" align="center" | [https://www.owasp.org/index.php/Image:OWASP_EU_Summit_2008_The_Owasp_Orizon_Project.ppt OWASP Orizon Project]<br>Paolo Perego (a.k.a. thesp0nge) |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:00 | | style="background:#7B8ABD" align="center" | 10:00 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Application Security Desk Reference (ADSR)<br>Leonardo Cavallari Militelli |
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#a0c0e0" align="center" | OWASP Live CD<br>Matt Tesauro |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:15 | | style="background:#7B8ABD" align="center" | 10:15 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Spanish Project<br>Juan Carlos Calderon |
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#a0c0e0" align="center" | [https://www.owasp.org/index.php/Image:OWASP_EU_Summit_2008_WebScarab_treasures.ppt WebScarab-NG]<br>Rogan Dawes |
|- | |- | ||
| style="background:#7B8ABD" align="center"| 10:30 | | style="background:#7B8ABD" align="center"| 10:30 | ||
| − | | colspan="5" style="background:# | + | | colspan="5" style="background:#C2C2C2" align="center" | Coffee Break |
|- | |- | ||
| style="background:#7B8ABD" align="center"| 10:45 | | style="background:#7B8ABD" align="center"| 10:45 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | .NET ESAPI<br>Alex Smolen |
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#a0c0e0" align="center" | |
| + | |- | ||
| + | | style="width:10%; background:#7B8ABD" align="center" | 11:00 | ||
| + | | colspan="4" style="width:90%; background:#F2F2F2" align="center" | Working Sessions Briefing<br>Dinis Cruz | ||
| + | |- | ||
| + | | style="width:10%; background:white" align="center"| | ||
| + | | colspan="4" style="width:90%; background:white" align="center" | Working Sessions | ||
|} | |} | ||
| − | + | {| style="width:80%" border="0" align="center" | | |
| − | + | | colspan="5" align="center" style="background:white" | | |
| − | |||
| − | {| style="width:80%" border="0" align="center" | | ||
| − | | colspan="5" align="center" style="background: | ||
| − | |||
| − | |||
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 11:15 - 13:00 | | style="width:10%; background:#7B8ABD" align="center" | 11:15 - 13:00 | ||
| − | | style="width:30%; background:# | + | | style="width:30%; background:#B3FF99" align="center" | Documentation Projects/Guides Integration and Unified 4.0 Version<br>Eduardo Neves |
| − | | style="width:30%; background:# | + | | style="width:30%; background:#B3FF99" align="center" | Browser Security<br>Arshan Dabirsiaghi |
| − | | style="width:30%; background:# | + | | style="width:30%; background:#B3FF99" align="center" | Tools Projects<br>Matt Tesauro |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 13:00 | | style="background:#7B8ABD" align="center" | 13:00 | ||
| − | | colspan="4" style="background:# | + | | colspan="4" style="background:#C2C2C2" align="center" | Lunch |
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| − | | colspan="4" style="background: | + | | colspan="4" style="width:90%; background:white" align="center" | Training Sessions |
|- | |- | ||
| − | | style="background:#7B8ABD" | | + | | style="background:#7B8ABD" align="center" | 14:00 |
| − | | style="background:# | + | | style="background:#c0a0a0" align="center" | The Art and Science of Threat Modeling Web Applications<br>Mano Paul |
| − | | style="background:# | + | | style="background:#c0a0a0" align="center" | [https://www.owasp.org/index.php/Image:SELinux-course-OWASP.pdf Web Server Hardening SELinux]<br>Pavol Luptak |
| − | | style="background:# | + | | style="background:#c0a0a0" align="center" | Offensive WebApp Hacking<br>Marco Slaviero |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 16:00 | | style="background:#7B8ABD" align="center" | 16:00 | ||
| − | | colspan="4" style="background:# | + | | colspan="4" style="background:#C2C2C2" align="center" | Coffee Break |
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| − | | colspan="4" style="background: | + | | colspan="4" style="width:90%; background:white" align="center" | Working Sessions |
|- | |- | ||
| − | | style="background:#7B8ABD" align="center" | 16:30 | + | | style="width:10%; background:#7B8ABD" align="center" | 16:30 |
| − | | colspan="4" style="background:# | + | | colspan="4" style="width:90%; background:#B3FF99" align="center" | ESAPI<br>Jeff Williams |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 18:30 | | style="background:#7B8ABD" align="center" | 18:30 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#B3FF99" align="center" | ASDR<br>Leonardo Cavallari |
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | .NET Project<br>Dinis Cruz |
|} | |} | ||
| Line 104: | Line 105: | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center"| 09:15 | | style="width:10%; background:#7B8ABD" align="center"| 09:15 | ||
| − | | colspan="4" style="width:80%; background:# | + | | colspan="4" style="width:80%; background:#F2F2F2" align="center" | Daily Briefing<br>Dinis Cruz |
| − | Dinis Cruz | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | colspan="2" style="width:30%; background:# | + | | colspan="2" style="width:30%; background:#FFDF80" align="center" | '''Standards and Education''' |
| − | + | | colspan="2" style="width:30%; background:#a0c0e0" align="center" | '''Tools''' | |
| − | | colspan="2" style="width:30%; background:# | ||
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:00 | | style="background:#7B8ABD" align="center" | 10:00 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | [http://www.owasp.org/index.php/Category:OWASP_Positive_Security_Project '''OWASP Positive Security (SoC 08)''']<br>Eduardo Vianna de Camargo Neves |
| − | Eduardo Vianna de Camargo Neves | + | | colspan="2" style="background:#a0c0e0" align="center" | [https://www.owasp.org/index.php/Image:OWASP_EU_Summit_2008_AcCoRuTe.pptx OWASP Access Control Rules Tester Project]<br>Andrew Petukhov |
| − | | colspan="2" style="background:# | ||
| − | Andrew Petukhov | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:15 | | style="background:#7B8ABD" align="center" | 10:15 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | [http://www.owasp.org/index.php/Category:OWASP_Education_Project '''OWASP Education''']<br>Sebastien Deleersnyder, Martin Knobloch |
| − | Sebastien Deleersnyder, Martin Knobloch | + | | colspan="2" style="background:#a0c0e0" align="center" | [https://www.owasp.org/index.php/Image:Teachable_static_analysis_workbench.pptx OWASP Teachable Static Analysis Workbench]<br>Dmitry Kozlov |
| − | | colspan="2" style="background:# | ||
| − | Dmitry Kozlov | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:30 | | style="background:#7B8ABD" align="center" | 10:30 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Internationalization Guidelines<br>Juan Carlos Calderon |
| − | Juan Carlos Calderon | + | | colspan="2" style="background:#a0c0e0" align="center" | [http://www.owasp.org/index.php/Category:OWASP_AppSensor_Project OWASP AppSensor]<br>Michael Coates |
| − | | colspan="2" style="background:# | ||
| − | Michael Coates | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:45 | | style="background:#7B8ABD" align="center" | 10:45 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | [https://www.owasp.org/index.php/Image:PASSWD.ppt PASSWD:Metrics and Vulnerabilities]<br>Lucilla Mancini |
| − | Lucilla Mancini | + | | colspan="2" style="background:#a0c0e0" align="center" | OWASP Backend Security Project<br>Carlo Pelliccioni |
| − | | colspan="2" style="background:# | ||
| − | Carlo Pelliccioni | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 11:00 | | style="background:#7B8ABD" align="center" | 11:00 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Open Review Project<br>Dan Cornell |
| − | Dan Cornell | + | | colspan="2" style="background:#a0c0e0" align="center" | [https://www.owasp.org/index.php/Image:Site_generator.pptx OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project]<br>Dmitry Kozlov |
| − | | colspan="2" style="background:# | ||
| − | Dmitry Kozlov | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 11:15 | | style="background:#7B8ABD" align="center" | 11:15 | ||
| − | | colspan="4" style="background:# | + | | colspan="4" style="background:#f2984c" align="center" | OWASP Global Committee Elections |
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 11:30 | | style="background:#7B8ABD" align="center" | 11:30 | ||
| − | | colspan="4" style="background:# | + | | colspan="4" style="background:#C2C2C2" align="center" | Coffee Break |
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| − | | colspan="4" style="background: | + | | colspan="4" style="width:90%; background:white" align="center" | Working Sessions |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 12:45 | | style="background:#7B8ABD" align="center" | 12:45 | ||
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | [[OWASP Working Session Education Project|OWASP Working Session Education Project]]<br>Sebastien Deleersnyder |
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | Testing Guide<br>Matteo Meucci |
| − | + | | colspan="2" style="background:#B3FF99" align="center" | Web Application Framework Security<br>Arshan Dabirsiaghi | |
| − | |||
| − | | colspan="2" style="background:# | ||
| − | |||
| − | |||
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 14:45 | | style="background:#7B8ABD" align="center" | 14:45 | ||
| − | | colspan="4" style="background:# | + | | colspan="4" style="background:#C2C2C2" align="center" | Lunch (During Working Sessions) |
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| − | | colspan="4" style="background: | + | | colspan="4" style="width:90%; background:white" align="center" | Training Sessions |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 15:00 | | style="background:#7B8ABD" align="center" | 15:00 | ||
| − | | style="background:# | + | | style="background:#c0a0a0" align="center" | Flash Player Security<br>Peleus Uhley |
| − | Peleus Uhley | + | | style="background:#c0a0a0" align="center" | OWASP Top 10<br>Sebastien Deleersnyder and Martin Knobloch |
| − | + | | style="background:#c0a0a0" align="center" | [https://www.owasp.org/index.php/Image:OWASP_EU_Summit_2008_WebScarab_treasures.ppt Uncovering WebScarab's Secret Treasures]<br>Rogan Dawes | |
| − | | style="background:# | + | | style="background:#c0a0a0" align="center" | [http://www.owasp.org/index.php/Image:Hacking_the_Owasp_Orizon.ppt Hacking the Orizon]<br>Paolo Perego |
| − | Sebastien Deleersnyder and Martin Knobloch | ||
| − | |||
| − | | style="background:# | ||
| − | Rogan Dawes | ||
| − | |||
| − | | style="background:# | ||
| − | Paolo Perego | ||
| − | |||
|- | |- | ||
| − | | style="background:#7B8ABD" align="center" | 17:00 | + | | style="background:#7B8ABD" align="center"| 17:00 |
| − | | colspan=" | + | | colspan="5" style="background:#C2C2C2" align="center" | Coffee Break |
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| + | | colspan="4" style="width:90%; background:white" align="center" | Working Sessions | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 17:30 | | style="background:#7B8ABD" align="center" | 17:30 | ||
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | Code Review Guide<br>Eoin Keary |
| − | + | | style="background:#B3FF99" align="center" | EU Funding for OWASP Projects<br>Carlos Serrao | |
| − | + | | style="background:#B3FF99" align="center" | OWASP Certification<br>Tom Brennan | |
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | Software Assurance Maturity Model<br>Pravir Chandra |
| − | |||
| − | |||
| − | | style="background:# | ||
| − | |||
| − | |||
| − | | style="background:# | ||
| − | |||
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 19:00 | | style="background:#7B8ABD" align="center" | 19:00 | ||
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | OWASP Website<br>Fabio Cerullo |
| − | + | | style="background:#B3FF99" align="center" | Metrics & Vulnerabilities<br>Lucilla Mancini | |
| − | + | | colspan="2" style="background:#B3FF99" align="center" | OWASP Orizon<br>Paolo Perego | |
| − | | style="background:# | ||
| − | |||
| − | |||
| − | | colspan="2" style="background:# | ||
| − | Paolo Perego | ||
| − | |||
|} | |} | ||
| Line 219: | Line 180: | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center"| 09:15 | | style="width:10%; background:#7B8ABD" align="center"| 09:15 | ||
| − | | colspan="5" style="width:80%; background:# | + | | colspan="5" style="width:80%; background:#F2F2F2" align="center" | Daily Briefing<br>Dinis Cruz |
| − | Dinis Cruz | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | colspan="2" style="width:30%; background:# | + | | colspan="2" style="width:30%; background:#FFDF80" align="center" | '''Technology''' |
| − | | colspan="3" style="width:30%; background:# | + | | colspan="3" style="width:30%; background:#a0c0e0" align="center" | '''Tools''' |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:00 | | style="background:#7B8ABD" align="center" | 10:00 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Classic ASP Security Project<br>Juan Carlos Calderon |
| − | Juan Carlos Calderon | + | | colspan="3" style="background:#a0c0e0" align="center" | OWASP Source Code Review<br>James Walden |
| − | | colspan="3" style="background:# | ||
| − | James Walden | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:15 | | style="background:#7B8ABD" align="center" | 10:15 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Ruby on Rails Security Project<br>Heiko Webers |
| − | Heiko Webers | + | | colspan="3" style="background:#a0c0e0" align="center" | OWASP Enigmaform and mod_Openpgp<br>Arturo Alberto Busleiman |
| − | | colspan="3" style="background:# | ||
| − | Arturo Alberto Busleiman | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 10:30 | | style="background:#7B8ABD" align="center" | 10:30 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Webslayer Project<br>Christian Martorella |
| − | Christian Martorella | + | | colspan="3" style="background:#a0c0e0" align="center" | OWASP Securing WebGoat using ModSecurity<br>Stephen Evans and Christian Folini |
| − | | colspan="3" style="background:# | ||
| − | Stephen Evans and Christian Folini | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 11:00 | | style="background:#7B8ABD" align="center" | 11:00 | ||
| − | | colspan="2" style="background:# | + | | colspan="2" style="background:#FFDF80" align="center" | OWASP Skavenger Project<br>Matthias Rohr |
| − | Matthias Rohr | + | | colspan="3" style="background:#a0c0e0" align="center" | OWASP AntiSamy.NET<br>Marcin Wielgoszewski |
| − | | colspan="3" style="background:# | ||
| − | Marcin Wielgoszewski | ||
|- | |- | ||
| − | | style="background:#7B8ABD" align="center" | 11:15 | + | | style="background:#7B8ABD" align="center"| 11:15 |
| − | | colspan="5" style="background:# | + | | colspan="5" style="background:#C2C2C2" align="center" | Coffee Break |
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| − | | colspan="5" style="background: | + | | colspan="5" style="width:90%; background:white" align="center" | Working Sessions |
|- | |- | ||
| style="background:#7B8ABD" align="center" | 11:30 | | style="background:#7B8ABD" align="center" | 11:30 | ||
| − | | style="background:# | + | | style="background:#B3FF99" align="center" | Top 10 2009<br>Dave Wichers |
| − | 2009 | + | | style="background:#B3FF99" align="center" | Intra Governmental Affairs<br>David Campbell |
| − | + | | style="background:#B3FF99" align="center" | SAMM v2 | |
| − | + | | style="background:#B3FF99" align="center" | Web Site | |
| − | + | | style="background:#B3FF99" align="center" | Handling Web MalWare | |
| − | | style="background:# | ||
| − | |||
| − | |||
| − | | style="background:# | ||
| − | |||
| − | | style="background:# | ||
| − | |||
| − | |||
| − | | style="background:# | ||
| − | |||
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 13:00 | | style="background:#7B8ABD" align="center" | 13:00 | ||
| − | | colspan="5" style="background:# | + | | colspan="5" style="background:#C2C2C2" align="center" | Lunch (During Working Sessions) |
| + | |- | ||
| + | | style="width:10%; background:white" align="center"| | ||
| + | | colspan="5" style="width:90%; background:white" align="center" | Training Sessions | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 14:00 | | style="background:#7B8ABD" align="center" | 14:00 | ||
| − | | | + | | style="background:#c0a0a0" align="center" | Ajax Security |
| − | + | | colspan="2" style="background:#c0a0a0" align="center" | Auditing Flash Applications<br>Peleus Uhley | |
| − | + | | style="background:#c0a0a0" align="center" | WebApp Assessment<br>Vicente Aguilera Diaz | |
| − | + | | style="background:#c0a0a0" align="center" | Mod Security<br>Lucas C. Ferreira | |
| − | |||
| − | | colspan="2" style="background:# | ||
| − | Peleus Uhley | ||
| − | |||
| − | | style="background:# | ||
| − | Vicente Aguilera Diaz | ||
| − | |||
| − | | style="background:# | ||
| − | Lucas C. Ferreira | ||
| − | |||
| − | |||
| − | |||
| − | |||
|- | |- | ||
| − | | style="background: | + | | style="width:10%; background:white" align="center"| |
| + | | colspan="5" style="width:90%; background:white" align="center" | Working Sessions | ||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 16:30 | | style="background:#7B8ABD" align="center" | 16:30 | ||
| − | | colspan="5" style="background:# | + | | colspan="5" style="background:#B3FF99" align="center" | Strategic Planning and Business Models compatible with OWASP values<br>Jeff Williams, Dinis Cruz, Dave Wichers, Sebastien Deleersnyder, Tom Brennan & Kate Hartmann and Paulo Combra |
| − | |||
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 18:30 | | style="background:#7B8ABD" align="center" | 18:30 | ||
| − | | style="background:# | + | | colspan="2" style="background:#B3FF99" align="center" | 2-Way Internationalization<br>Juan Carlos Calderon & Sebastien Deleersnyder |
| − | + | | colspan="2" style="background:#B3FF99" align="center" | Best Practices for Chapter Leaders<br>Georg Hess | |
| − | + | | colspan="2" style="background:#B3FF99" align="center" | Live CD & DVD<br>Matt Tesauro | |
| − | | style="background:# | ||
| − | |||
| − | |||
| − | | | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
|- | |- | ||
| style="background:#7B8ABD" align="center" | 20:00 | | style="background:#7B8ABD" align="center" | 20:00 | ||
| − | | colspan="5" style="background:# | + | | colspan="5" style="background:#C2C2C2" align="center" | Gala Dinner |
|- | |- | ||
| style="background:#7B8ABD " align="center" | 22:00 | | style="background:#7B8ABD " align="center" | 22:00 | ||
| − | | colspan="5" style="background:# | + | | colspan="5" style="background:#C2C2C2" align="center" | OWASP Band |
|} | |} | ||
{| style="width:80%" border="0" align="center" | {| style="width:80%" border="0" align="center" | ||
| − | | colspan=" | + | | colspan="2" align="center" style="background:#4058A0; color:white" | Agenda for Friday, November 7th, 2008 |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 10:00 | | style="width:10%; background:#7B8ABD" align="center" | 10:00 | ||
| − | | | + | | style="width:80%; background:#F2F2F2" align="center" | Daily Briefing<br>Dinis Cruz |
| − | Dinis Cruz | ||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 10:15 | | style="width:10%; background:#7B8ABD" align="center" | 10:15 | ||
| − | | | + | | style="width:80%; background:#F2F2F2" align="center" | OWASP AppSec Agenda 2009: Working Session Outcomes |
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Documentation Projects/Guides Integration and Unified 4.0 Version<br>Eduardo Neves |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Browser Security<br>Arshan Dabirsiaghi |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | ESAPI<br>Jeff Williams |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Tools Projects<br>Matt Tesauro |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Code Review Guide<br>Eoin Keary |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | OWASP Certification<br>Tom Brennan |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Software Assurance Maturity Model<br>Pravir Chandra |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Top 10 2009<br>Dave Wichers |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Intra Governmental Affairs<br>David Campbell |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Best Practices for Chapter Leaders<br>Georg Hess |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 11:15 | | style="width:10%; background:#7B8ABD" align="center" | 11:15 | ||
| − | | | + | | style="width:80%; background:#f2984c" align="center" | Coffee Break and Vote (put your dots on the wall) |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 11:30 | | style="width:10%; background:#7B8ABD" align="center" | 11:30 | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Live CD & DVD<br>Matt Tesauro |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | ADSR<br>Leonardo Cavallari |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Education Project<br>Sebastien Deleersnyder |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Web Application Framework Security<br>Arshan Dabirsiaghi |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Testing Guide<br>Matteo Meucci |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | OWASP Censorship<br>Tom Brennan |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | EU Funding for OWASP Projects<br>Carlos Serrao |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | OWASP Website<br>Fabio Cerullo |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | OWASP Orizon<br>Paolo Perego |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Handling Web MalWare |
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | 2-Way Internationalization<br>Juan Carlos Calderon |
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" | | | style="width:10%; background:#7B8ABD" | | ||
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Portuguese Public & Private Organizations<br>Carlos Serrao |
| − | |||
|- | |- | ||
| − | | style="width:10%; background:#7B8ABD" align="center" | | + | | style="width:10%; background:#7B8ABD" align="center" | |
| − | | | + | | style="width:80%; background:#C2C2C2" align="center" | Winter of Code 2009<br>Dinis Cruz and Sebastien Deleersnyder |
| − | |||
| − | |||
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 13:00 | | style="width:10%; background:#7B8ABD" align="center" | 13:00 | ||
| − | | | + | | style="width:80%; background:#F2F2F2" align="center" | Lunch |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center"| 14:00 | | style="width:10%; background:#7B8ABD" align="center"| 14:00 | ||
| − | | | + | | style="width:80%; background:#f2984c" align="center" | Board Meeting |
|- | |- | ||
| style="width:10%; background:#7B8ABD" align="center" | 17:00 | | style="width:10%; background:#7B8ABD" align="center" | 17:00 | ||
| − | | | + | | style="width:80%; background:#f2984c" align="center" | Announcement of Summit Procedings |
|} | |} | ||
Latest revision as of 17:04, 27 November 2008
EVENT AGENDA
| Agenda for Monday, November 3rd, 2008 | ||||
| 13:00 | Lunch | |||
| Training Sessions | ||||
| 15:00 - 17:00 | Securing WebGoat with ModSecurity Stephen Craig Evans |
WebSec Apps for Managers and Executives Mano Paul |
OWASP Testing Guide Matteo Meucci | |
| 19:00 | Summit Briefing Dinis Cruz and Summit Organization Team | |||
| 20:00 | Dinner | |||
| Agenda for Tuesday, November 4th, 2008 | |||||
| 08:00 | Registration | ||||
| 09:00 | Summit Keynote Dinis Cruz and Summit Organization Team | ||||
| Documents | Tools | ||||
| 09:30 | OWASP Testing Guide Matteo Meucci |
OWASP JSP Testing Tool Jason Li | |||
| 09:45 | OWASP Code Review Guide Eoin Keary |
OWASP Orizon Project Paolo Perego (a.k.a. thesp0nge) | |||
| 10:00 | OWASP Application Security Desk Reference (ADSR) Leonardo Cavallari Militelli |
OWASP Live CD Matt Tesauro | |||
| 10:15 | OWASP Spanish Project Juan Carlos Calderon |
WebScarab-NG Rogan Dawes | |||
| 10:30 | Coffee Break | ||||
| 10:45 | .NET ESAPI Alex Smolen |
||||
| 11:00 | Working Sessions Briefing Dinis Cruz | ||||
| Working Sessions | |||||
| 11:15 - 13:00 | Documentation Projects/Guides Integration and Unified 4.0 Version Eduardo Neves |
Browser Security Arshan Dabirsiaghi |
Tools Projects Matt Tesauro | |
| 13:00 | Lunch | |||
| Training Sessions | ||||
| 14:00 | The Art and Science of Threat Modeling Web Applications Mano Paul |
Web Server Hardening SELinux Pavol Luptak |
Offensive WebApp Hacking Marco Slaviero | |
| 16:00 | Coffee Break | |||
| Working Sessions | ||||
| 16:30 | ESAPI Jeff Williams | |||
| 18:30 | ASDR Leonardo Cavallari |
.NET Project Dinis Cruz | ||
| Agenda for Wednesday, November 5th, 2008 | |||||
| 09:15 | Daily Briefing Dinis Cruz | ||||
| Standards and Education | Tools | ||||
| 10:00 | OWASP Positive Security (SoC 08) Eduardo Vianna de Camargo Neves |
OWASP Access Control Rules Tester Project Andrew Petukhov | |||
| 10:15 | OWASP Education Sebastien Deleersnyder, Martin Knobloch |
OWASP Teachable Static Analysis Workbench Dmitry Kozlov | |||
| 10:30 | OWASP Internationalization Guidelines Juan Carlos Calderon |
OWASP AppSensor Michael Coates | |||
| 10:45 | PASSWD:Metrics and Vulnerabilities Lucilla Mancini |
OWASP Backend Security Project Carlo Pelliccioni | |||
| 11:00 | OWASP Open Review Project Dan Cornell |
OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project Dmitry Kozlov | |||
| 11:15 | OWASP Global Committee Elections | ||||
| 11:30 | Coffee Break | ||||
| Working Sessions | |||||
| 12:45 | OWASP Working Session Education Project Sebastien Deleersnyder |
Testing Guide Matteo Meucci |
Web Application Framework Security Arshan Dabirsiaghi | ||
| 14:45 | Lunch (During Working Sessions) | ||||
| Training Sessions | |||||
| 15:00 | Flash Player Security Peleus Uhley |
OWASP Top 10 Sebastien Deleersnyder and Martin Knobloch |
Uncovering WebScarab's Secret Treasures Rogan Dawes |
Hacking the Orizon Paolo Perego | |
| 17:00 | Coffee Break | ||||
| Working Sessions | |||||
| 17:30 | Code Review Guide Eoin Keary |
EU Funding for OWASP Projects Carlos Serrao |
OWASP Certification Tom Brennan |
Software Assurance Maturity Model Pravir Chandra | |
| 19:00 | OWASP Website Fabio Cerullo |
Metrics & Vulnerabilities Lucilla Mancini |
OWASP Orizon Paolo Perego | ||
| Agenda for Thursday, November 6th, 2008 | ||||||
| 09:15 | Daily Briefing Dinis Cruz | |||||
| Technology | Tools | |||||
| 10:00 | OWASP Classic ASP Security Project Juan Carlos Calderon |
OWASP Source Code Review James Walden | ||||
| 10:15 | OWASP Ruby on Rails Security Project Heiko Webers |
OWASP Enigmaform and mod_Openpgp Arturo Alberto Busleiman | ||||
| 10:30 | OWASP Webslayer Project Christian Martorella |
OWASP Securing WebGoat using ModSecurity Stephen Evans and Christian Folini | ||||
| 11:00 | OWASP Skavenger Project Matthias Rohr |
OWASP AntiSamy.NET Marcin Wielgoszewski | ||||
| 11:15 | Coffee Break | |||||
| Working Sessions | ||||||
| 11:30 | Top 10 2009 Dave Wichers |
Intra Governmental Affairs David Campbell |
SAMM v2 | Web Site | Handling Web MalWare | |
| 13:00 | Lunch (During Working Sessions) | |||||
| Training Sessions | ||||||
| 14:00 | Ajax Security | Auditing Flash Applications Peleus Uhley |
WebApp Assessment Vicente Aguilera Diaz |
Mod Security Lucas C. Ferreira | ||
| Working Sessions | ||||||
| 16:30 | Strategic Planning and Business Models compatible with OWASP values Jeff Williams, Dinis Cruz, Dave Wichers, Sebastien Deleersnyder, Tom Brennan & Kate Hartmann and Paulo Combra | |||||
| 18:30 | 2-Way Internationalization Juan Carlos Calderon & Sebastien Deleersnyder |
Best Practices for Chapter Leaders Georg Hess |
Live CD & DVD Matt Tesauro | |||
| 20:00 | Gala Dinner | |||||
| 22:00 | OWASP Band | |||||
| Agenda for Friday, November 7th, 2008 | |
| 10:00 | Daily Briefing Dinis Cruz |
| 10:15 | OWASP AppSec Agenda 2009: Working Session Outcomes |
| Documentation Projects/Guides Integration and Unified 4.0 Version Eduardo Neves | |
| Browser Security Arshan Dabirsiaghi | |
| ESAPI Jeff Williams | |
| Tools Projects Matt Tesauro | |
| Code Review Guide Eoin Keary | |
| OWASP Certification Tom Brennan | |
| Software Assurance Maturity Model Pravir Chandra | |
| Top 10 2009 Dave Wichers | |
| Intra Governmental Affairs David Campbell | |
| Best Practices for Chapter Leaders Georg Hess | |
| 11:15 | Coffee Break and Vote (put your dots on the wall) |
| 11:30 | Live CD & DVD Matt Tesauro |
| ADSR Leonardo Cavallari | |
| Education Project Sebastien Deleersnyder | |
| Web Application Framework Security Arshan Dabirsiaghi | |
| Testing Guide Matteo Meucci | |
| OWASP Censorship Tom Brennan | |
| EU Funding for OWASP Projects Carlos Serrao | |
| OWASP Website Fabio Cerullo | |
| OWASP Orizon Paolo Perego | |
| Handling Web MalWare | |
| 2-Way Internationalization Juan Carlos Calderon | |
| Portuguese Public & Private Organizations Carlos Serrao | |
| Winter of Code 2009 Dinis Cruz and Sebastien Deleersnyder | |
| 13:00 | Lunch |
| 14:00 | Board Meeting |
| 17:00 | Announcement of Summit Procedings |