This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Los Angeles"

From OWASP
Jump to: navigation, search
Line 8: Line 8:
  
  
== Next&nbsp;Chapter Meeting:&nbsp; Wednesday,&nbsp;September 28, 2011 7:00 P.M.&nbsp;- 8:30 P.M. <br> ==
+
== Next&nbsp;Chapter Meeting:&nbsp; Wednesday,&nbsp;October 26, 2011 7:00 P.M.&nbsp;- 8:30 P.M. <br> ==
  
 
Symantec<br>900 Corporate Pointe<br>Culver City, CA 90230<br>
 
Symantec<br>900 Corporate Pointe<br>Culver City, CA 90230<br>
  
Please RSVP: http://owasp-september2011.eventbrite.com
+
Please RSVP: http://owasp-october2011.eventbrite.com
 
   
 
   
  
 
----
 
----
  
==== Topic: Deep XSS Defense ====
+
==== Topic: Scalable AppSec ====
This talk will discuss the past methods used for XSS defense that were only partially effective. Learning from these lessons, will will also discuss present day defensive methodologies that are effective, but place an undue burden on the developer. We will then finish with a discussion of future XSS defense mythologies that shift the burden of XSS defense from the developer to various frameworks. These include auto-escaping template technologies, browser-based defenses such as Content Security Policy, and Javascript sandboxes such as the Google CAJA project and JSReg.
+
 
 +
A talk on metrics and assessment practices that scale well - more details forthcoming.
  
  
Line 35: Line 36:
  
  
 +
==== Topic: Time Based SQL Injections ====
 +
 +
We’ll cover Time Based SQL Injection attacks to show a dangerous flavor of SQL injections. We’ll show how by using time delay functions and heavy query techniques these attacks can be very effective by defying sanitization techniques. The speaker will also show some examples of SQL injection attacks like BART, UK Police etc. and show a live DEMO. Some prevention technique will also be covered.
 +
 +
====Speaker: Muhammad Omar Khan ====
 +
 +
Muhammad Omar Khan is the current Security Team Lead at CIA (Cenzic Intelligent Analysis) Labs. His previous experience includes: Hacker, Researcher on Sensor Networks at USC,ISI.
  
====Meeting Sponsor: PKWARE====
 
  
 +
====Meeting Sponsor: WhiteHat Security====
  
[[Image: PKWARE.jpg]]
+
 
 +
[[Image: Whitehatlogo-medium.png‎]]
 
<br><br>
 
<br><br>
  
More than 30,000 global corporations and 200 government agencies worldwide rely on PKWARE to help protect against security breaches, reduce the risk of non compliance and safeguard sensitive data. The PKWARE Solution is the only complete system for reducing, securing, moving and storing data across the extended enterprise, both internally and externally, from mainframes to servers to desktops and into the cloud. PKWARE is the industry standard for portability, ensuring data security and cross-platform computing. The PKWARE Solution is used billions of times a day to manage risks associated with data security breaches while avoiding increased storage costs with data reduction of up to 95% and improving service delivery. PKWARE is a privately-held company based in Milwaukee, WI with additional offices in New York, Ohio and the United Kingdom.
+
WhiteHat Security is the leading provider of website risk management solutions that protect critical data, ensure compliance and narrow the window of risk. WhiteHat Sentinel, the company’s flagship product family, is the most accurate and cost-effective website vulnerability management solution available, delivering the visibility, flexibility, and control that organizations need to prevent website attacks. www.whitehatsec.com.
 +
 
 +
 
 +
 
  
 
----
 
----
Line 53: Line 65:
  
 
== Other Events ==
 
== Other Events ==
 
ISSA Los Angeles chapter invites us to their September dinner meeting
 
on September 21, 2011. They are extending us a discounted rate of $20
 
for dinner, WITH reservations and online payment. It is a great
 
opportunity to meet recruiters specialized in information security
 
jobs at national level. Let's not miss out on this!
 
 
 
Please RSVP at http://www.issa-la.org/2011/08/23/september-2011-issa-la-monthly-member-meeting/
 
 
  
  

Revision as of 20:14, 29 September 2011

Local News

Sign up for OWASP Los Angeles mailing list, very low volume and spam free.
https://lists.owasp.org/mailman/listinfo/owasp-losangeles

<paypal>Los Angeles</paypal>


Next Chapter Meeting:  Wednesday, October 26, 2011 7:00 P.M. - 8:30 P.M.

Symantec
900 Corporate Pointe
Culver City, CA 90230

Please RSVP: http://owasp-october2011.eventbrite.com



Topic: Scalable AppSec

A talk on metrics and assessment practices that scale well - more details forthcoming.


Speaker: Jim Manico

Jim Manico has been an active member of OWASP since 2008.


Jim is the founder, producer and host of the OWASP Podcast Series. As of July 2011 there are 86 shows that have entailed Jim working over 500 hours. Jim is grateful to the many guests who have made the show a success.


Jim is also the chair of the OWASP Connections Committee where he manages the OWASP Blog, twitter feed and press communications for OWASP. He feels that these activities are directly inline with the OWASP core mission of spreading awareness.


He has also been a significant contributor and manager of the OWASP Cheatsheet Series. He has worked on the XSS, DOM XSS, SQL Injection, Cryptographic Storage, Forgot Password and other topics in this series.


Topic: Time Based SQL Injections

We’ll cover Time Based SQL Injection attacks to show a dangerous flavor of SQL injections. We’ll show how by using time delay functions and heavy query techniques these attacks can be very effective by defying sanitization techniques. The speaker will also show some examples of SQL injection attacks like BART, UK Police etc. and show a live DEMO. Some prevention technique will also be covered.

Speaker: Muhammad Omar Khan

Muhammad Omar Khan is the current Security Team Lead at CIA (Cenzic Intelligent Analysis) Labs. His previous experience includes: Hacker, Researcher on Sensor Networks at USC,ISI.


Meeting Sponsor: WhiteHat Security

Whitehatlogo-medium.png

WhiteHat Security is the leading provider of website risk management solutions that protect critical data, ensure compliance and narrow the window of risk. WhiteHat Sentinel, the company’s flagship product family, is the most accurate and cost-effective website vulnerability management solution available, delivering the visibility, flexibility, and control that organizations need to prevent website attacks. www.whitehatsec.com.




Would you like to speak at an OWASP Los Angeles Meeting?

Call for Papers (CFP) is NOW OPEN. To speak at upcoming OWASP Los Angeles meetings please submit your BIO and talk abstract via email to Tin Zaw. When we accept your talk, it will be required to use the Powerpoint OWASP Template.


Other Events

ISSA-LA holds a lunch meeting on the 3rd Wed of each month, for more information visit www.issa-la.org.


Archives of Previous Meetings

2011 Meetings

2010 Meetings

2009 Meetings

2008 Meetings

List of presentations available from past meetings


Los Angeles Chapter


The AppSec USA 2010 conference received rave reviews. Thanks to all the volunteers and great speakers who helped make it a success!

http://2010.AppSecUSA.org

Check out the videos: http://vimeo.com/user4863863/videos

AppSec Logo.jpg