This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "AppSec US 2010, CA"

From OWASP
Jump to: navigation, search
Line 97: Line 97:
 
|-
 
|-
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 08:30-08:45  
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 08:30-08:45  
| align="center" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(242, 242, 242);" | Welcome to OWASP AppSec US, 2010
+
| align="center" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(242, 242, 242);" | Welcome to OWASP AppSec US, 2010 (Crystal Cove Auditorium)
 
|-
 
|-
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 08:45-9:30  
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 08:45-9:30  
| align="center" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(252, 252, 150);" | #Keynote: Jeff Williams
+
| align="center" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(252, 252, 150);" | #Keynote: Jeff Williams (Crystal Cove Auditorium)
 
|-
 
|-
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 9:30-10:15
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 9:30-10:15
| align="center" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(252, 252, 150);" | #Keynote: Chenxi Wang
+
| align="center" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(252, 252, 150);" | #Keynote: Chenxi Wang (Crystal Cove Auditorium)
 
|-
 
|-
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 10:15-10:35  
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 10:15-10:35  
| align="left" colspan="3" style="width: 90%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Break - Expo - CTF kick-off
+
| align="left" colspan="3" style="width: 90%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Break - Expo - CTF kick-off (Emerald Bay)
 
|-
 
|-
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 10:10-10:45
+
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 10:35-11:20
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" | [[Image:OWASP AppSec Research 2010 Research R.gif]] [[#BitFlip: Determine a Data's Signature Coverage from Within the Application]] ([[Media:OWASP_AppSec_Research_2010_BitFlip_by_Poehls.pdf|pdf]])
+
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" | How I met your Girlfriend, ''Sammy Kamkar''<br>  
''Henrich Christopher Poehls, University of Passau''<br>  
 
  
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 165, 122);" | [[Image:OWASP AppSec Research 2010 Presentation P.gif]] [[#CsFire: Browser-Enforced Mitigation Against CSRF]] ([[Media:OWASP_AppSec_Research_2010_CsFire_by_Desmet_and_DeRyck.pdf|pdf]])
+
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 165, 122);" | Solving Real-World Problems with an Enterprise Security API (ESAPI), ''Chris Schmidt, ServiceMagic''<br>  
''Lieven&nbsp;Desmet&nbsp;and&nbsp;Philippe&nbsp;De&nbsp;Ryck,&nbsp;Katholieke Universiteit Leuven''<br>  
 
 
 
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(153, 255, 153);" | [[Image:OWASP AppSec Research 2010 Presentation P.gif]] [[#Deconstructing ColdFusion]] ([[Media:OWASP_AppSec_Research_2010_Deconstructing_ColdFusion_by_Eng.pdf|pdf]])
 
''Chris Eng,&nbsp;Veracode''
 
  
 +
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(153, 255, 153);" | Microsoft Security Development Lifecycle for Agile Development, ''Nick Coblentz, AT&T''
 
|-
 
|-
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 10:45-11:10
+
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 11:20-11:30
| align="left" colspan="3" style="width: 90%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Break - Expo - CTF kick-off, '''Coffee break sponsoring position open''' ($2,000)
+
| align="left" colspan="3" style="width: 90%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Break - Expo - CTF  
|-
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 11:10-11:45
 
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" | [[Image:OWASP AppSec Research 2010 Research R.gif]] [[#Towards Building Secure Web Mashups]] ([[Media:OWASP_AppSec_Research_2010_Secure_Mashups_by_DeRyck.pdf|pdf]])
 
''M Decat, P De Ryck, L Desmet, F Piessens, W Joosen,&nbsp;Katholieke Universiteit Leuven''
 
 
 
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 165, 122);" | [[Image:OWASP AppSec Research 2010 Presentation P.gif]] [[#New Insights into Clickjacking]] ([[Media:OWASP_AppSec_Research_2010_Clickjacking_by_Balduzzi.pdf|pdf]]) ''Marco Balduzzi,&nbsp;Eurecom<br><br>''
 
 
 
<br>
 
 
 
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(153, 255, 153);" | [[Image:OWASP AppSec Research 2010 Presentation P.gif]] [[#How to Render SSL Useless]] ([[Media:Ivan_Ristic_-_Breaking_SSL_-_OWASP.pdf|pdf]])
 
''Ivan Ristic, Qualys<br>''
 
 
 
 
|-
 
|-
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 11:55-12:30
+
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 11:30-12:15
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" |  
+
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" | State of SL on the Internet - 2010 Survey, Results and Conclusions, ''Ivan Ristic, Qualys''<br>
[[Image:OWASP AppSec Research 2010 Research R.gif]] [[#Busting Frame Busting]] ([[Media:OWASP_AppSec_Research_2010_Busting_Frame_Busting_by_Rydstedt.pdf|pdf]])
 
  
''Gustav Rydstedt,&nbsp;Stanford Web Security Research''<br>
 
  
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 165, 122);" | [[Image:OWASP AppSec Research 2010 Presentation P.gif]] [[#Web Frameworks and How They Kill Traditional Security Scanning]] ([[Media:OWASP_AppSec_Research_2010_Frameworks_Security_by_Hang.pdf|pdf]])
+
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" | Into the Rabbit Hole: Execution Flow-based Web Application Testing, ''Rafal Los, Hewlett-Packard''<br>
''Christian Hang and Lars Andren,&nbsp;Armorize Technologies''  
 
  
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(153, 255, 153);" | [[Image:OWASP AppSec Research 2010 Demo D.gif]] [[#The State of SSL in the World]] ([[Media:OWASP_AppSec_Research_2010_State_of_SSL_by_Boman.pdf|pdf]])
+
''Michael Boman, Omegapoint<br>''
+
| align="left" style="width: 30%; background: none repeat scroll 0% 0% rgb(188, 133, 122);" | Threat Modeling Best Practices, Robert Zigweid, IOActive<br>
  
 
|-
 
|-
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 12:30-13:45
+
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 12:15-1:15
| align="left" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Lunch - Expo - CTF, Lunch sponsor: [[Image:OWASP AppSec Research 2010 IIS logo for program.png]]
+
| align="left" colspan="3" style="width: 80%; background: none repeat scroll 0% 0% rgb(194, 194, 194);" | Lunch - Expo - CTF
 
|-
 
|-
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 13:45-14:20  
 
| style="width: 10%; background: none repeat scroll 0% 0% rgb(123, 138, 189);" | 13:45-14:20  

Revision as of 17:33, 16 July 2010


AppSec USA 2010 Banner

UC Irvine Conference Center | CLICK HERE TO REGISTER


Welcome

Please Visit the AppSecUS 2010 Web Page for more information.

Registration is open!

https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=3c8f8c26-a4b3-40d6-9daa-1f541ea0ccc2

OWASP member registration $325 Non-member registration $375 Student registration (ID required at conference) $250

Call for papers/training extended to June 30th!

We are accepting presentation proposals!

http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=Call_for_Papers.2FTraining

News April 8th

Our final keynote has just accepted! Bill Cheswick from AT&T Research and Jeff Williams of Aspect Security round out our keynotes!

Lumetathumb.jpegJeffWilliams2.jpg


News March 25th

David Rice of Geekonomics and HD Moore of Metasploit/Rapid7 will be keynote speakers!

Hdm.hshot.white.jpgRice color small.jpg


Press Release January 23rd, 2010 -- Event Announced!

The Global Conferences Committee is excited to announce the date and location of the OWASP AppSec US 2010 Conference. AppSec US 2010 will be held September 7th through September 10th, 2010 and will be hosted by the Orange County and Los Angeles Chapters at the University of California, Irvine, the only school in the University of California system with a dedicated school of Information and Computer Science. More information, including the call for speakers & the call for training will be sent shortly.

Who Should Attend AppSec USA 2010:

  • Application Developers
  • Application Testers and Quality Assurance
  • Application Project Management and Staff
  • Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff
  • Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance
  • Security Managers and Staff
  • Executives, Managers, and Staff Responsible for IT Security Governance
  • IT Professionals Interesting in Improving IT Security


The full AppSec USA Schedule coming soon.

You can register for the conference soon



| style="width: 110px; font-size: 95%; color: rgb(0, 0, 0);" | |}

Agenda/Schedule

Conference Day 1 - September 9th, 2010



Track 1 - Crystal Cove Auditorium Track 2 - Pacific Ballroom Track 3 - Doheny Beach
07:30-08:30 Registration and Breakfast + Coffee
08:30-08:45 Welcome to OWASP AppSec US, 2010 (Crystal Cove Auditorium)
08:45-9:30 #Keynote: Jeff Williams (Crystal Cove Auditorium)
9:30-10:15 #Keynote: Chenxi Wang (Crystal Cove Auditorium)
10:15-10:35 Break - Expo - CTF kick-off (Emerald Bay)
10:35-11:20 How I met your Girlfriend, Sammy Kamkar
Solving Real-World Problems with an Enterprise Security API (ESAPI), Chris Schmidt, ServiceMagic
Microsoft Security Development Lifecycle for Agile Development, Nick Coblentz, AT&T
11:20-11:30 Break - Expo - CTF
11:30-12:15 State of SL on the Internet - 2010 Survey, Results and Conclusions, Ivan Ristic, Qualys


Into the Rabbit Hole: Execution Flow-based Web Application Testing, Rafal Los, Hewlett-Packard


Threat Modeling Best Practices, Robert Zigweid, IOActive
12:15-1:15 Lunch - Expo - CTF
13:45-14:20 OWASP AppSec Research 2010 Research R.gif #(New) Object Capabilities and Isolation of Untrusted Web Applications (pdf)

Sergio Maffeis, Imperial College, London

OWASP AppSec Research 2010 Presentation P.gif #Beyond the Same-Origin Policy (pdf)

Jasvir Nagra and Mike Samuel, Google

OWASP AppSec Research 2010 Demo D.gif #SmashFileFuzzer - a New File Fuzzer Tool (pdf)

Komal Randive, Symantec

14:30-15:05 OWASP AppSec Research 2010 Demo D.gif #Security Toolbox for .NET Development and Testing (pdf)

Johan Lindfors and Dag König, Microsoft

OWASP AppSec Research 2010 Demo D.gif #Cross-Site Location Jacking (XSLJ) (not really) (pdf)

David Lindsay, Cigital
Eduardo Vela Nava, sla.ckers.org

OWASP AppSec Research 2010 Demo D.gif #Owning Oracle: Sessions and Credentials (pdf)

Wendel G. Henrique and Steve Ocepek, Trustwave

15:05-15:30 Break - Expo - CTF, Coffee break sponsoring position open ($2,000)
15:30-16:05 OWASP AppSec Research 2010 Demo D.gif #Value Objects a la Domain-Driven Security: A Design Mindset to Avoid SQL Injection and Cross-Site Scripting (pdf)

Dan Bergh Johnsson, Omegapoint

OWASP AppSec Research 2010 Presentation P.gif #Automated vs. Manual Security: You Can't Filter "The Stupid" (pdf not available yet)

David Byrne and Charles Henderson, Trustwave

OWASP AppSec Research 2010 Research R.gif #Session Fixation - the Forgotten Vulnerability? (pdf)

Michael Schrank and Bastian Braun, University of Passau
Martin Johns, SAP Research

16:15-17:00 Panel Discussion: "Is Application Security a Losing Battle?" ([[Media:|pdf]])
19:00-23:00 Stockholm City Hall, photo by Yanan Li Gala Dinner at Stockholm City Hall
Sponsored by
OWASP AppSec Research 2010 Google logo for program.png
The Golden Hall, photo by Yanan Li

Registration

Registration Now Open!

CLICK HERE TO REGISTER

OWASP Membership ($50 annual membership fee) gets you a discount of $50.

$375 Until 7/31/2010 Non-Members After 7/31/2010 - $445
$325 Until 7/31/2010 OWASP Members After 7/31/2010 - $395
$250 Students with valid Student ID
$375 Until 7/31/2010 New Registration Option! Become an OWASP Member and attend the event!
$1350 2-Day Training Course
$675 1-Day Training Course

Who Should Attend AppSec USA 2010:

  • Application Developers
  • Application Testers and Quality Assurance
  • Application Project Management and Staff
  • Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff
  • Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance
  • Security Managers and Staff
  • Executives, Managers, and Staff Responsible for IT Security Governance
  • IT Professionals Interesting in Improving IT Security


For student discount, attendees must present proof of enrollment when picking up your badge.

Volunteer

Volunteers Needed!

Get involved!

We will take all the help we can get to pull off the best Web Application Security Conference of the year! Volunteers get free admission and invitation to the VIP event. This is your chance to rub elbows with the big players and mingle with potential networking contacts or even future employers!


Please contact neil(at)owasp.org to volunteer for a specific area:

  • Security
  • Speakers and Trainers
  • Vendors
  • Facilities

More opportunities and areas will be added as time goes on. Our File:Volunteer Sheet.doc can be downloaded which outlines some of the responsibilities and available positions. Note: this document references the the DC conference last year, this is just for a general guideline. Updated document coming soon.


Training

T1. Web Security Testing - 2-Days - $1350
Summary

Instructor: Joe Basirico, Security Innovation

T2. Building Secure Ajax and Web 2.0 Applications - 2-Days - $1350
Summary

Instructor: Dave Wichers: Aspect_logo.gif

T3. Assessing and Exploiting Web Applications with Samurai - WTF - 2-Days - $1350
Summary

Instructor: Justin Serle, InGuardians

T4. Application Security Leadership Essentials - 2-Days - $1350
Summary

Instructor: Jeff Williams: Aspect_logo.gif

T5. Software Security Remediation: How to Fix Application Vulnerabilities 1-Day - Sept 7th- $675
Summary

Instructor: Dan Cornell: AppSecDC2009-Sponsor-denim.gif

T6. Live CD 1-Day - Sept 8th- $675
Summary

Instructor: Matt Tesauro: TrustwaveLogo.jpg

Venue

UC Irvine Conference Center Center

AppSec USA 20010 will be taking place at the UC Irvine Conference Center in Irvine, CA.


Hotel

Hyatt main.gif

We have reached a deal with Hyatt Regency of Irvine. The standard room rate will be $109. The hotel will be offering a shuttle service to and from both the UC Irvine campus as well as the John Wayne Airport!

Space is limited so be sure to book sooner than later. Please use this link to reserve a room https://resweb.passkey.com/go/owasp2010

UC Irvine also has special arrangements with local  hotels here

Sponsors

Sponsors

We are currently soliciting sponsors for the AppSec US 2010 Conference. Please refer to our List of Sponsorship Opportunities (or PDF).

Please contact Kate Hartmann for more information.

Slots are going fast so contact us to sponsor today!

    

Platinum Sponsors

[File:Qualys-468-60.png]
 

Gold Sponsors

Ibmneg blurgb.jpg Fortify logo AppSec Research 2010.png
 

Silver Sponsors

AppSecDC2009-Sponsor-fishnet.gif Acunetix logo 200.png Barracuda Color Logo.jpg
 
 

Organizational Sponsors

Isc2 logo.gif
 

Reception Sponsors

Coffee Sponsors

Travel

Traveling to the OC Metro Area