This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Toronto

From OWASP
Revision as of 01:26, 1 June 2017 by Yuk Fai Chan (talk | contribs) (Announcing June 2017 chapter event.)

Jump to: navigation, search

OWASP Toronto Chapter.jpg


OWASP Toronto

Welcome to the Toronto chapter homepage. The chapter is managed by Andre Rochefort, Yuk Fai Chan, Opheliar Chan and Nish Bhalla.


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


The mailing list archive can be accessed from here.

Our chapter's Meetup.com page is can be accessed here.

Chapter Supporters

We would like to thank the following organizations for their support and contribution to the local Toronto chapter!

Gold Local Chapter Supporter

Hewlett Packard Enterprise

Silver Local Chapter Supporter

Checkmarx

Global Contributing Corporate Member & Local Event Supporter

Security Compass

Local Event Supporter

Amazon



Date/Time: June 13, 2017, 6:00 - 8:00 PM EST

Location: Suite 500, 257 Adelaide St. W., Toronto, ON

Space is limited, so please RSVP here to confirm your presence.

Session Description:

The Node.js Highway: Attacks Are At Full Throttle

Node.js is the drive-and-go language and its popularity is soaring. Five years after its debut, and the language’s framework boasts more 2M downloads a month. Before accelerating too quickly, it is important to understand the power – and corresponding mishaps – of this language. In this talk, we demonstrate new attack techniques against applications built on top of the Node.js language. Attacks include:

  • Application-layer DDoS attacks. Bringing a server to its knees with just 4(!) requests.
  • Password exposure attacks. Leveraging the “Forgot My Password” feature of applications in order to reveal the passwords of all the application’s users
  • Business logic attacks. Running malicious code on all machines of users of the applications when exploiting a weak business feature.

Presenter Bio:

Susan St.Clair, CWAPT

Solution Engineer – Checkmarx

Susan currently works with organizations to help implement secure coding practices as part of their SDLC as part of the Checkmarx GTA team. She has over 15 years of experience working with application teams in the software industry.

She was previously a product manager and solution engineer with Codiscope, now part of Synopsys.