This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Poland"

From OWASP
Jump to: navigation, search
m (typos)
Line 47: Line 47:
 
19 00 - 19 15 Break
 
19 00 - 19 15 Break
 
   
 
   
19 15 - 20 00 '''Google bug bounty - is it worth it or just a waste of time?''', Michał Bentowski, securitum.pl
+
19 15 - 20 00 '''Google bug bounty - is it worth it or just a waste of time?''', Michał Bentkowski, securitum.pl
  
 
In the presentation I will talk about my two year adventures with Google’s bug bounty programme. I will share my general feeling about organisational issues like: communication or payments, but most importantly I will show a few specific bugs I have submitted. These will particuarly include some unusual XSS bugs, exploiting quirks in both browsers and web servers.
 
In the presentation I will talk about my two year adventures with Google’s bug bounty programme. I will share my general feeling about organisational issues like: communication or payments, but most importantly I will show a few specific bugs I have submitted. These will particuarly include some unusual XSS bugs, exploiting quirks in both browsers and web servers.

Revision as of 21:38, 2 September 2015

Welcome

OWASP Poland

Welcome to the Poland chapter homepage. The original Polish Chapter was founded in June 2007 by Andrzej Targosz and Robert Pajak. The chapter leader is Wojciech Dworakowski (since 2011). Acting Chapter Board members are (since 2011): Michal Kurek, Marek Zmyslowski, Tomasz Polanski, Mateusz Olejarka, Paweł Krawczyk (till September 2013).

If you have any questions about previous activities (2009-2011) do not hesitate to contact Przemyslaw Skowron
If you have any questions about previous activities (2007-2009) do not hesitate to contact Andrzej Targosz
<paypal>Poland</paypal>


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


OWASP Poland on social networks:

Chapter Supporters

OWASP Poland thanks its Chapter Supporters:
Allegro-group.jpg - Gold Chapter Supporter.
Qualys logo.png - Silver Chapter Supporter,
LP logo.jpg - Silver Chapter Supporter,
Logo securing-150px.png - Silver Chapter Supporter.
If your company wishes to support our chapter, please contact Wojciech Dworakowski (terms and conditions: https://www.owasp.org/index.php/Membership).

OWASP Kraków 10.09.2015

On 10. september at 6 p.m. we meet in Tech Space (Wyczółkowskiego 7 street) in Kraków. Both talks will be in English.

Agenda:

18 00 - 18 15 Intro

18 15 - 19 00 From bug to Metasploit module, Ewerson (Crash) Guimaraes, EPAM

The Local File Incluison, privilege escalation, CSRF and command execution are old bugs, but still present in applications available over internet.

Over the past two years were about 300 publications related to this bugs in applications that can be downloaded and easily installed on a server exposed in internet.

These statistics not include institutional sites and systems that are developed specifically internally or to a particular customer, that is, there are hundreds of thousands of vulnerable systems.

This talk will show a effective way to exploit this flaws and furthermore, show the way to better understanding and explore the bugs effectively and how to create a Metasploit module/exploit.

19 00 - 19 15 Break

19 15 - 20 00 Google bug bounty - is it worth it or just a waste of time?, Michał Bentkowski, securitum.pl

In the presentation I will talk about my two year adventures with Google’s bug bounty programme. I will share my general feeling about organisational issues like: communication or payments, but most importantly I will show a few specific bugs I have submitted. These will particuarly include some unusual XSS bugs, exploiting quirks in both browsers and web servers.

20 00 - ... Outro

Registration: https://www.eventbrite.com/e/owasp-meeting-10092015-tickets-18296621688