This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Austin"

From OWASP
Jump to: navigation, search
Line 5: Line 5:
  
 
=Upcoming Events=
 
=Upcoming Events=
=== April OWASP Chapter Meeting===
+
=== May Austin Security Professionals Happy Hour (Sponsored by Rapid 7)===
  
'''When:''' April 24th, from 11:30a-1:00pm
+
'''When''' : Thursday, May 10th from 5-7 PM.
  
'''Topic:''': Anatomy of Advanced Email Attacks (Aaron Estes, Cigital)
 
  
Abstract:  Email attacks comprise an overwhelming majority of the daily attacks on modern enterprise.  The leading mitigation strategy is a combination of user awareness training and email filtering.  This talk outlines a proposed solution that brings email risk and awareness information down to the client level in order to better equip end users in making secure decisions when using email.
+
'''Where''': Sherlocks Baker Street Pub and Grill at the corner of 183 and Burnet.  
 
 
Anti-spam capabilities have been incorporated into email client applications for some time now.  These are usually in the form of junk boxes or email filters that attempt to identify spam or other unwanted email.  Most anti-spam clients use bayesian filtering to determine whether an email is spam or not spam, typically using word combinations and statistical analysis to make a determination.  Many experts also advise wary email users to examine the raw email headers in order to attempt to find evidence of an email attack.  While this is not bad advise, it is however a highly technical process and one cannot expect the majority of email users to be able to carry out and act upon this advice.  This is the problem that the proposed Advanced Email Risk Classification and Recipient Decision Assistance solution attempts to solve.  The operating name for this solution is Phish Finder.
 
 
 
'''Speaker:''' Aaron Estes, Cigital
 
 
 
Aaron Estes came to Cigital from Lockheed Martin where he spend 10 years in the software engineering and security engineering fields. He began his information security career as a system security engineer on the F-35 program.  Aaron has spent the last 5 years as a security engineer and penetration tester for Lockheed Martin Enterprise Business Services specializing in application penetration testing and user awareness/social engineering testing.  Aaron is also a professor at Southern Methodist University in Dallas where he teaches senior and graduate level security courses.  He has nearly completed his Doctor of Engineering in Software Engineering at Southern Methodist University, has a Masters in Software Engineering from Southern Methodist University and has a Bachelors in Computer Science from University of Texas.  Aaron is a Certified Information System Security Professional.
 
 
 
'''Cost:''' Free, of course, but please RVSV!
 
 
 
'''Food:''' Oh yeah, Taco Deli time! Please RSVP so we'll be sure to have
 
enough for all!
 
 
 
'''Location:''' National Instruments, 11500 N. Mopac.
 
 
 
'''Questions?''' call: David Hughes (512) 589-4623
 
 
 
'''RSVP:''' http://www.eventbrite.com/event/3182987401
 
 
 
'''Attend Remotely!'''
 
 
 
Attend remotely at:
 
 
1.  Please join my meeting.
 
https://www3.gotomeeting.com/join/299008790
 
 
 
2.  Use your microphone and speakers (VoIP) - a headset is recommended.  Or, call in using your telephone.
 
  
Argentina (toll-free): 0 800 444 1466
+
'''What is it?''': The Austin Security Professionals happy hour is a monthly gathering of information security professionals from the Austin area, heavily represented by OWASP and ISSA membership. It is a time to enjoy some drinks and food provided by our sponsor, an to get to know other InfoSec professionals. Come on down and hang out with a bunch of hackers and geeks!
Australia (toll-free): 1 800 458 097
 
Australia: +61 (0) 3 9008 6767
 
Austria (toll-free): 0 800 802088
 
Austria: +43 (0) 7 2088 1047
 
Belarus (toll-free): 8 820 0011 0214
 
Belgium (toll-free): 0 800 26116
 
Belgium: +32 (0) 28 08 4368
 
Brazil (toll-free): 0 800 761 1760
 
Canada (toll-free): 1 888 455 1389
 
Canada: +1 (647) 723-0900
 
China (toll-free): 4001 542674
 
Czech Republic (toll-free): 800 040808
 
Denmark (toll-free): 8090 1924
 
Denmark: +45 (0) 69 91 89 28
 
Finland (toll-free): 0 800 552044
 
Finland: +358 (0) 942 59 7850
 
France (toll-free): 0 800 903 851
 
France: +33 (0) 182 880 172
 
Germany (toll-free): 0 800 589 0052
 
Germany: +49 (0) 892 2061 193
 
Hong Kong SAR China (toll-free): 800 905 505
 
Iceland (toll-free): 800 9869
 
India (toll-free): 000 800 650 1700
 
Indonesia (toll-free): 007 803 011 0395
 
Ireland (toll-free): 1 800 947 677
 
Ireland: +353 (0) 19 030 010
 
Israel (toll-free): 1 809 212 875
 
Italy (toll-free): 800 132384
 
Italy: +39 0 247 92 13 01
 
Japan (toll-free): 00 531 122 098
 
Luxembourg (toll-free): 800 22104
 
Malaysia (toll-free): 1 800 81 5373
 
Mexico (toll-free): 01 800 607 0197
 
Netherlands (toll-free): 0 800 265 8469
 
Netherlands: +31 (0) 208 080 219
 
New Zealand (toll-free): 0 800 45 2202
 
New Zealand: +64 (0) 9 280 6302
 
Norway: +47 75 80 32 07
 
Panama (toll-free): 00 800 226 8832
 
Peru (toll-free): 0 800 54682
 
Philippines (toll-free): 1 800 1651 0716
 
Poland (toll-free): 00 800 1213979
 
Portugal (toll-free): 800 784 461
 
Russia (toll-free): 810 800 29664011
 
Singapore (toll-free): 800 120 5615
 
South Africa (toll-free): 0 800 983 867
 
South Korea (toll-free): 00 798 6517 480
 
Spain (toll-free): 0 900 804 771
 
Spain: +34 911 82 9906
 
Sweden (toll-free): 0 200 439 940
 
Sweden: +46 (0) 852 500 186
 
Switzerland (toll-free): 0 800 740 393
 
Switzerland: +41 (0) 435 0167 13
 
Taiwan (toll-free): 00 806 651 908
 
Thailand (toll-free): 001 800 658 131
 
Ukraine (toll-free): 0 800 50 0641
 
United Kingdom (toll-free): 0 800 014 8182
 
United Kingdom: +44 (0) 207 151 1853
 
United States (toll-free): 1 877 568 4106
 
United States: +1 (914) 339-0025
 
Uruguay (toll-free): 000 413 598 4110
 
Vietnam (toll-free): 120 65 157
 
  
Access Code: 299-008-790
 
Audio PIN: Shown after joining the meeting
 
  
Meeting ID: 299-008-790
+
'''Our Sponsor: Rapid 7'''
  
GoToMeeting®
+
Rapid7 is a leading provider of vulnerability management and penetration testing solutions.  The Company’s Nexpose and Metasploit products empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7's solutions are being used by more than 2,000 enterprises and government agencies in more than 65 countries worldwide, while the Company's free products are downloaded more than one million times per year and enhanced further by over 125,000 security community users and contributors. Rapid7 has been recognized as one of the fastest growing security companies by Inc. Magazine, while their products have been awarded best in category ratings by Gartner, Forrester and SC Magazine. For more information about Rapid7, please visit http://www.rapid7.com.
Online Meetings Made Easy™
 
  
 +
'''RSVP''' : http://www.eventbrite.com/event/3471578585
  
  
Line 134: Line 43:
  
 
=Record Hall of Meetings=
 
=Record Hall of Meetings=
 +
 +
'''When:''' April 24th, 11:30a-1:00pm
 +
 +
'''Topic: ''' Anatomy of Advanced Email Attacks (Aaron Estes, Cigital)
 +
 +
Abstract:  Email attacks comprise an overwhelming majority of the daily attacks on modern enterprise.  The leading mitigation strategy is a combination of user awareness training and email filtering.  This talk outlines a proposed solution that brings email risk and awareness information down to the client level in order to better equip end users in making secure decisions when using email.
 +
 +
Anti-spam capabilities have been incorporated into email client applications for some time now.  These are usually in the form of junk boxes or email filters that attempt to identify spam or other unwanted email.  Most anti-spam clients use bayesian filtering to determine whether an email is spam or not spam, typically using word combinations and statistical analysis to make a determination.  Many experts also advise wary email users to examine the raw email headers in order to attempt to find evidence of an email attack.  While this is not bad advise, it is however a highly technical process and one cannot expect the majority of email users to be able to carry out and act upon this advice.  This is the problem that the proposed Advanced Email Risk Classification and Recipient Decision Assistance solution attempts to solve.  The operating name for this solution is Phish Finder.
 +
 +
'''Who: ''' Aaron Estes, Cigital
 +
 +
Aaron Estes came to Cigital from Lockheed Martin where he spend 10 years in the software engineering and security engineering fields. He began his information security career as a system security engineer on the F-35 program.  Aaron has spent the last 5 years as a security engineer and penetration tester for Lockheed Martin Enterprise Business Services specializing in application penetration testing and user awareness/social engineering testing.  Aaron is also a professor at Southern Methodist University in Dallas where he teaches senior and graduate level security courses.  He has nearly completed his Doctor of Engineering in Software Engineering at Southern Methodist University, has a Masters in Software Engineering from Southern Methodist University and has a Bachelors in Computer Science from University of Texas.  Aaron is a Certified Information System Security Professional.
 +
 +
'''Cost:''' Always Free
 +
 +
'''RSVP:''' http://www.eventbrite.com/event/3182987401
 +
 +
 +
 
'''When:'''April 19th, from 5pm-7pm
 
'''When:'''April 19th, from 5pm-7pm
  

Revision as of 16:07, 1 May 2012

OWASP Austin

Welcome to the Austin chapter homepage. The chapter leadership includes: David Hughes, President/Conference Chair, Ben Broussard, Vice President,Josh Sokol, Conference Chair, James Wickett, Conference Chair, Rich Vazquez, Board Member, Greg Genung, Board Member


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG




May Austin Security Professionals Happy Hour (Sponsored by Rapid 7)

When : Thursday, May 10th from 5-7 PM.


Where: Sherlocks Baker Street Pub and Grill at the corner of 183 and Burnet.

What is it?: The Austin Security Professionals happy hour is a monthly gathering of information security professionals from the Austin area, heavily represented by OWASP and ISSA membership. It is a time to enjoy some drinks and food provided by our sponsor, an to get to know other InfoSec professionals. Come on down and hang out with a bunch of hackers and geeks!


Our Sponsor: Rapid 7

Rapid7 is a leading provider of vulnerability management and penetration testing solutions. The Company’s Nexpose and Metasploit products empower organizations to obtain accurate, actionable and contextual intelligence into their threat and risk posture. Rapid7's solutions are being used by more than 2,000 enterprises and government agencies in more than 65 countries worldwide, while the Company's free products are downloaded more than one million times per year and enhanced further by over 125,000 security community users and contributors. Rapid7 has been recognized as one of the fastest growing security companies by Inc. Magazine, while their products have been awarded best in category ratings by Gartner, Forrester and SC Magazine. For more information about Rapid7, please visit http://www.rapid7.com.

RSVP : http://www.eventbrite.com/event/3471578585



Future Speakers and Events

  • April 24, 2012 - 11:30 AM to 1 PM - Austin OWASP Meeting: Anatomy of Advanced Email Attacks (Aaron Estes, Cigital)
  • May 10, 2012 - 5 PM to 7 PM - Austin Security Professionals Happy Hour (Sponsored by Rapid7)
  • May 29, 2012 - 11:30 AM to 1 PM - Austin OWASP Meeting: "Closing the window of opportunity"(Jim Manico and Siri De Licori of WhiteHat Security)
  • May 29, 2012 - 1:00 PM to 5:00 PM - Secure Coding Bootcamp with Jim Manico.
  • June 14, 2012 - 5 PM to 7 PM - Austin Security Professionals Happy Hour (Sponsored by WhiteHat Security)
  • June 26, 2012 - 11:30 AM to 1 PM - Austin OWASP Meeting: 'The Jane Austen Software Development Model'(Wendy Nather, 451Group)
  • July 12, 2012 - 5 PM to 7 PM - Austin Security Professionals Happy Hour
  • July 31, 2012 - 11:30 AM to 1 PM - Austin OWASP Meeting: OWASP Lightning Talks
  • August 9, 2012 - 5 PM to 7 PM - Austin Security Professionals Happy Hour
  • August 28, 2012 - 11:30 AM to 1 PM - Austin OWASP Meeting
  • September 13, 2012 - 5 PM to 7 PM - Austin Security Professionals Happy Hour
  • September 25, 2012 - 11:30 AM to 1 PM - Austin OWASP Meeting
  • October 23-26, 2012 - 8 AM to 5 PM - AppSec USA/LASCON 2012 in Austin, TX!
  • November 2012 - No Meeting (Happy Holidays!)
  • December 2012 - No Meeting (Happy Holidays!)

How to add a new Austin article

You can follow the instructions to make a new Austin article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the Austin category:

[[Category:Austin]]