This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Los Angeles"

From OWASP
Jump to: navigation, search
Line 44: Line 44:
 
== '''Next OWASP Meeting'''==
 
== '''Next OWASP Meeting'''==
 
''**NOTE: Date for this event **''
 
''**NOTE: Date for this event **''
==''' 7pm May 28, 2014 at Symantec offices, 900 Corporate Pointe, Culver City, CA 90230'''==
+
==''' 7pm June 25, 2014 at Symantec offices, 900 Corporate Pointe, Culver City, CA 90230'''==
  
   '''Topic:  Cloud Security Through Threat Modeling
+
   '''Topic:  Cashing Out – How Malware is Used to Attack ATMs
  
One of the most effective tools developers can implement in their
+
Recently a group of 10 criminals were arrested in Mexico for infecting ATMs with malware and, like a scene from a movie, emptying the ATMs of cash. A group of Ukrainian hackers were also arrested in China using another ATM infecting scheme. This talk will discuss recent ATM malware that has been discovered, how it works and how the attackers are leveraging infected ATMs.  
security development lifecycle programs is threat modeling. Robert will
 
discuss how effective threat modeling techniques enable developers to
 
uncover security vulnerabilities before code is even written. Together
 
they will reveal how threat modeling also applies to cloud environments.
 
Whether building a hybrid model, purely commodity cloud, or Virtual
 
Private Cloud (VPC) environment, threat modeling helps identify the
 
attack surface area and likely threat vectors. Finally, they will explain
 
to attendees that threat modeling allows developers and operations
 
personnel to address vulnerabilities as enterprises migrate to the cloud.  
 
  
  '''Speaker:  Robert Zigweid
+
Since the proof is in the pudding, Liam will bring a physical, one tonne, ATM  for a demonstration of how these threats work in the real world, by dispensing cash via a text message!
 +
  
Robert Zigweid As an IOActive Director of Services, Robert Zigweid is responsible to both perform and ensure quality on engagements, working with clients to discover and solve network and application problems that threaten their business goals and assets. Mr. Zigweid is an accomplished developer and application tester, with advanced skills in the creation and analysis of systems architecture and threat modeling.
+
  '''Speaker:  Liam O'Murchu
  
In addition to his direct efforts on penetration tests, security reviews,
+
Liam manages a team of reverse engineers investigating the latest malicious attacks and analyzing cutting edge malware. He was formerly Manager of Security Response Operations for North America at Symantec, where he had responsibility for ensuring immediate response to computer security incidents of all size involving malicious software.
and network and application audits, Mr. Zigweid frequently contributes to
 
the advancement of more stable, secure systems through his research and
 
development. His research‹and the resultant presentations at top industry
 
conferences‹furthers the formal understanding of application and network
 
security for audiences at varying levels of technical fluency.
 
  
Mr. Zigweid also helped develop IOActive's secure coding and Software
 
Development Lifecycle training courses, sharing his deep understanding of
 
industry best practices and guidelines to help our clients develop
 
applications capable of resisting both internal and external threats.
 
  
 
== '''Sponsor: IOActive '''==
 
== '''Sponsor: IOActive '''==

Revision as of 17:45, 4 June 2014

Welcome to the Los Angeles Chapter!

Donatenow.jpg

Single Meeting Supporter: Organizations that wish to support the OWASP Los Angeles Chapter with a 100% tax deductible donation enable the OWASP Foundation to continue its mission

Get the following benefits::

- Meet upwards of 60-90 potential new clients
- Be recognized as a local supporter by posting your company logo on the local chapter page and on our Meetup site(Image size for logos: gif, jpg or png with a size of 150px X 45px at 72dpi or 55px X 80px at 72dpi) 
- Have your marketing write-up included in e-mail blasts sent prior to a monthly meeting.
- Have a table at local chapter meeting 
- Promote your products and services
- Bring a raffle prize to gather business cards

Contact us #Los Angeles Chapter for general questions relating to sponsorship and donations

Announcements

OWASP Los Angeles received the BEST Chapter Leaders award at AppSec USA NY


logo.png

We are on Meetup. Please join our community there.

If you are unable to access Meetup from your work computer as a result of filtering of social sites, we recommend that you view it on your smart phone or via your personal computer.
http://www.meetup.com/OWASP-Los-Angeles/


Become an OWASP Member TODAY

Support your LA Chapter: only $50 for the entire year!
https://www.owasp.org/index.php/Individual_Member


2013 December Holiday Party at Daily Grill in LA

Holiday.jpg


Next OWASP Meeting

**NOTE: Date for this event **

7pm June 25, 2014 at Symantec offices, 900 Corporate Pointe, Culver City, CA 90230

  Topic:  Cashing Out – How Malware is Used to Attack ATMs

Recently a group of 10 criminals were arrested in Mexico for infecting ATMs with malware and, like a scene from a movie, emptying the ATMs of cash. A group of Ukrainian hackers were also arrested in China using another ATM infecting scheme. This talk will discuss recent ATM malware that has been discovered, how it works and how the attackers are leveraging infected ATMs.

Since the proof is in the pudding, Liam will bring a physical, one tonne, ATM for a demonstration of how these threats work in the real world, by dispensing cash via a text message!


  Speaker:   Liam O'Murchu

Liam manages a team of reverse engineers investigating the latest malicious attacks and analyzing cutting edge malware. He was formerly Manager of Security Response Operations for North America at Symantec, where he had responsibility for ensuring immediate response to computer security incidents of all size involving malicious software.


Sponsor: IOActive

IO.JPG

IOActive is the only security consultancy with a global presence and deep expertise that spans hardware, software, and wetware. We secure the Global 1000 in all facets of their enterprise and product portfolios in an era when vulnerabilities are mounting and threats evolve daily. Our team of internationally recognized experts partner with you to solve your toughest security challenges. Core competencies include penetration testing, reverse engineering, code review, social engineering, and hardware security assessments. With expertise far beyond off-the-shelf tools, IOActive conducts in-depth analysis of information systems, software/hardware architecture, and source code using leading information risk management security frameworks and carefully focused threat models.

Please RSVP here: http://www.meetup.com/OWASP-Los-Angeles/events/


Would you like to speak at an OWASP Los Angeles Meeting?

Call for Papers (CFP) is NOW OPEN. To speak at upcoming OWASP Los Angeles meetings please submit your BIO and talk abstract via email to Richard Greenberg OR Stuart Schwartz. The talk must be vendor neutral and its content be available under Creative Common 3.0 license.


Upcoming OWASP Meetings

   Topic: Securing the SDLC in the real world
   Speaker: Jim Manico 

The earlier you address security in the engineering of software, the less expensive it will be for your organization. There are many who will tell you that you need to change all of your current processes around building software so it is more secure. Many of those forces are consultants charging high rates to help you deeply modify what you are doing today. This talk will will take the opposite approach. How can you add a few reasonable and mostly lightweight processes to how you build software today to make it more secure? Software development is like driving a boat. You need to look ahead make small changes to steer effectively.

Other Events



Archives of Previous Meetings

2014 Meetings

2013 Meetings

2012 Meetings

2011 Meetings

2010 Meetings

2009 Meetings

2008 Meetings

Presentation Archive


Los Angeles Chapter

Volunteers: Yev Avidon and Mikhael Felker
OWASP Wiki: Mike Francis
The Los Angeles chapter was founded by Cassio Goldschmidt.


The AppSec USA 2010 conference received rave reviews. Thanks to all the volunteers and great speakers who helped make it a success!


Web archive: http://2010.AppSecUSA.org

Videos: http://vimeo.com/user4863863/videos

AppSec Logo.jpg