This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Austin

From OWASP
Revision as of 22:25, 8 September 2019 by Tchandler (talk | contribs) (OWASP Austin Chapter Meeting, September 24, 2019)

Jump to: navigation, search

OWASP Austin

Welcome to the Austin chapter homepage. The chapter leadership includes: Tiana Chandler, Chapter Leader (see Chapter Leadership for full listing of Austin Chapter leadership team).
Join OWASP Austin mailing list to receive notifications of local events.


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG



Listing of Upcoming Events

Austin Security Professionals Happy Hour sponsored by Synack, September 12, 2019

This will be our final happy hour for the year.

When: Thursday, September 12th, 5:00 pm - 7:00 pm

Where: Baby A's, 9505-B Stonelake Blvd, Austin, Texas 78759 (corner of Stonelake and York Blvd, between Hwy 183 and Mopac). We meet in the area inside the restaurant, in the far left corner.

What: The Austin Security Professionals Happy Hour is a monthly event coordinated by the Austin OWASP and Capital of Texas ISSA Chapters and sponsored by various companies. We try to meet every second Thursday of the month from January to September (but occasionally we make schedule adjustments when needed). The event is an informal social gathering of local information security professionals. If you're involved with InfoSec or even if you have an interest, come on out for drinks, good food and conversation.

Sponsor: Synack

Synack, the most trusted crowdsourced security testing platform, delivers smarter penetration testing to security teams who need a scalable, efficient way to test their attack surfaces on a continuous cadence and get actionable results. Synack’s crowdsourced penetration test is powered by the world's most skilled and trusted ethical hackers and augmented by AI-enabled technology to give customers the best of human intelligence and machine intelligence. Headquartered in Silicon Valley with regional offices around the world, Synack protects leading global banks, federal agencies, DoD classified assets, and close to $1 trillion in Fortune 500 revenue. A 4-time CNBC Disruptor 50 company, Synack was founded in 2013 by former NSA security experts Jay Kaplan, CEO, and Dr. Mark Kuhr, CTO. For more information, please visit www.synack.com.
Synack will have a pair of Apple Airpods to raffle off ... must be present to win.

RSVP: https://aus-sec-happy-hour-2019-09.eventbrite.com

Back to Top

OWASP Austin Chapter Meeting, September 24, 2019

When: Tuesday, September 24th @ 11:45 AM - 1:00 PM

Where: National Instruments, 11500 N. Mopac.Building C

Title: OAuth 2.0 Misimplementation, Vulnerabilities and Best Practices

OAuth 2.0 is an authorization framework that enables third party applications to obtain temporary limited authorization to access a protected resource on behalf of a resource owner. The framework is defined by authorization interactions that are each scoped to the type of client obtaining authorization and the type or types of resource owners that must grant access. Diverging from these defined scopes can open up various interception and redirect attack vectors that can grant a malicious actor access to protected resources. For this talk, we will be discussing Public Clients vs Confidential Clients, User Authentication vs Client Authentication, Proof Key for Code Exchange (PKCE) for Public Clients, and how restricting certain OAuth flows to either Public or Confidential Clients is required to mitigate unauthorized access to protected resources.

Speaker: Pak Foley

Pak Foley is a Security Engineer at Procore Technologies. He has specialized in Identity and Access Management with a focus on architecting enterprise OAuth and SAML solutions for authentication and authorization throughout distributed systems. With a passion for OAuth in particular, he has spent much of his time seeking out and mitigating vulnerabilities from misimplemented OAuth solutions and contributed to the open source Rails OAuth provider, Doorkeeper. His passion for securing web applications has prompted his recent move from IAM to security.

Food: Tacodeli. PLEASE RSVP ahead of time so we can be sure to have enough for all! Arriving at 11:30 AM gives you time to get some food and find a seat. We try to start the meeting around 11:50 AM

Only those who RSVP will be eligible for any drawings/giveaways that may take place!

RSVP: https://owasp-austin-2019-september.eventbrite.com

Or if you can not attend we should be broadcasting the meeting via Zoom: https://zoom.us/j/913160162

NOTE: This will be our last chapter meeting of the year. Our next one will be in January. Of course we hope to see you all next month at LASCON. https://lascon.org

Back to Top

LASCON X

When: Tuesday & Wednesday, October 22-23, 2019 (Pre-Conference Training), Thursday & Friday, October 24-25, 2019 (Conference Sessions)

Where: Norris Conference Center, 2525 W. Anderson Lane, Suite 365, Austin, Texas 78757

What: The Lonestar Application Security Conference (LASCON) is an OWASP conference held annually in Austin, TX. It is a gathering of 400+ web app developers, security engineers, mobile developers and information security professionals. LASCON is held in Texas where more Fortune 500 companies call home than any other state and it is held in Austin which is a hub for startups in the state of Texas. At LASCON, leaders at these companies along with security architects and developers gather to share cutting-edge ideas, initiatives, and technology advancements.

This will be our 10th year anniversary of LASCON. We are getting an early start to create a memorable conference.

Back to Top

How to add a new Austin article

You can follow the instructions to make a new Austin article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the Austin category:

[[Category:Austin]]