This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Mumbai

From OWASP
Revision as of 15:42, 6 July 2006 by Dharmeshmm (talk | contribs) (Local News)

Jump to: navigation, search

OWASP Mumbai

Welcome to the Mumbai chapter homepage. The chapter leader is Dharmesh M Mehta


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


Local News

Next Meeting - Tentative Monday July 31st 2006 [03:00 PM - 5:00 PM] 

Invitations are OPEN for all to present at the Next OWASP Mumbai Meet.

The meeting is to be scheduled tentatively on Monday, 31st July 2006 from 3:00 to 5:00 PM.

Venue and Sponsor Details:

Tech Mahindra Ltd..

Tech Mahindra Limited. Wing 1, Oberoi Estate Gardens, Chandivali, Andheri (E), Mumbai 400 072, Maharashtra, India.

If you would like to speak, please drop in a mail at [email protected]

CPE Credits for CISSP's 

ISC2 has approved 1 CPE for each hour of an OWASP local chapter meeting.

Chapter leader will have a sign up sheet with at least First Name, Last Name, and the date of the OWASP Meeting. After the meeting, the single sheet will be signed once by a chapter lead as proof of attendance, scanned into a .PDF, and emailed out to the chapter members with the meeting minutes so they have a copy for records and can claim CPE credits.


Minutes of Meeting - First Meeting - Saturday June 24th 2006 [09:30 - 12:00] 

With the welcome address by Anuradha, the first meeting of Mumbai Chapter embarked. Right from giving a brief introduction about OWASP and its aim, Anuradha explained the focus of OWASP as a voluntary organization aiming at contributing to the knowledge as a part of sharing it. Apart from it, Anuradha briefed about OWASP Top 10 Project and OWASP Guide to building Secure Application.

Richard presented on Secure Coding Fundamentals and elucidated the Cost factor inculcated due to insecure code resulting in Network Cost, Productivity Cost and so on. Further explaining the basic reasons of threat to code, he explained how the mistakes done by the Programmers, I/O, API Abuse, Environment & Configuration and Time & State were responsible for Security flaws in an application. Moving ahead, Richard laid down a few principles to be followed as Secure Coding – General Guidelines for all the languages and specific Secure Coding Guidelines for C & C++, Java and .NET

With Threat Analysis & Modeling Process, Dharmesh explained the steps followed as Threat Modeling Process starting from Defining Application Requirement, Application Architecture, and Modeling Threats looking at CIA feature of Security Basics. The aim covered to look towards gathering the information needed from application development teams in order to mock out the potential threats that are inherit in the software application they build starting from the very inception of the software birth. Giving the demonstration of Threat Analysis and Modeling Tool v2.0 with the basic example of its functionality, Dharmesh presented the Threat Modeling in real scenario.

Shalini and Runa explained how password can be lost or manipulated in a real life scenario and it dealt with the countermeasures to be taken to avoid it. The topics covered under it included Stealing Password using different methods as – Browser’s Refresh, Browser’s Memory, Remember feature, Forget Password feature and last but not the least SQL Injection. The role of Browser’s Viewing Tool available showed a clear picture of how password could be easily cracked.


Mumbai Chapter - First Meeting - Saturday June 24th 2006 [09:30 - 12:00] 

Everyone is welcome to join us at our regular chapter meetings.

Time: 9:30 AM - 12:00 PM

If you have any items you want added to the agenda, post your ideas to our mailing list.

If you would like to speak at the event or sponsor, contact Dharmesh M Mehta before 20th June.

Current Agenda


1. 09:30 - 09:45 Introduction to OWASP Mumbai

Anuradha Srinivasan, Software Engineer with Mastek, is working with the Application Security Assurance Team for the last 6 months. She has 2 and a half years of experience in Java development. She is currently involved in conducting Security Assessments and trainings for projects across Mastek

2. 09:45 - 10:30 Secure Coding Fundamentals

Richard Lewis, Security Consultant with TechMahindra, has 8 years of information security experience. Before joining Tech Mahindra, he was employed with Tata Consultancy Services (TCS). Richard currently works in the e-security consulting group of Tech Mahindra and is working on building a security fabric for secure software development. Richard has a programming background in C, C++ and MFC. A MS Windows guy, he has a flair for secure software development.

10:30 - 11:00 Food and Beverages

3. 11:00 - 11:30 Threat Modeling

Dharmesh M Mehta, Software Engineer with Mastek, has been with the Application Security Assurance Team for around 2 years. He is involved in conducting security assessments and conducting security workshops for the developer community. He is also a Certified Ethical Hacker.

4. 11:30 - 12:00 5 ways to lose your user's password

Shalini Gupta and Runa Dwibedi are Associate Security Consultants in Paladion Networks. They are also authors of a monthly online magazine Palisade (focused on Application security). They will be speaking on the ways to lose a user’s password.


Venue and Sponsor Details:

Mastek Ltd.

Mastek Millennium Center, A-7 Sec-I Millennium Business Park,

Mahape, Navi Mumbai - 400 710.

Please contact Dharmesh M Mehta before 23th June if you are attending the meeting.


OWASP Moves to MediaWiki Portal - 11:23, 20 May 2006 (EDT)

OWASP is pleased to announce the arrival of OWASP 2.0!

OWASP 2.0 utilizes the MediaWiki portal to manage and provide the latest OWASP related information. Enjoy!