This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Austin

From OWASP
Revision as of 05:21, 23 September 2019 by Tchandler (talk | contribs) (2019)

Jump to: navigation, search

OWASP Austin

Welcome to the Austin chapter homepage. The chapter leadership includes: Tiana Chandler, Chapter Leader (see Chapter Leadership for full listing of Austin Chapter leadership team).
Join OWASP Austin mailing list to receive notifications of local events.


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG



Listing of Upcoming Events

OWASP Austin Chapter Meeting, September 24, 2019

When: Tuesday, September 24th @ 11:45 AM - 1:00 PM

Where: National Instruments, 11500 N. Mopac.Building C

Title: OAuth 2.0 Misimplementation, Vulnerabilities and Best Practices

OAuth 2.0 is an authorization framework that enables third party applications to obtain temporary limited authorization to access a protected resource on behalf of a resource owner. The framework is defined by authorization interactions that are each scoped to the type of client obtaining authorization and the type or types of resource owners that must grant access. Diverging from these defined scopes can open up various interception and redirect attack vectors that can grant a malicious actor access to protected resources. For this talk, we will be discussing Public Clients vs Confidential Clients, User Authentication vs Client Authentication, Proof Key for Code Exchange (PKCE) for Public Clients, and how restricting certain OAuth flows to either Public or Confidential Clients is required to mitigate unauthorized access to protected resources.

Speaker: Pak Foley

Pak Foley is a Security Engineer at Procore Technologies. He has specialized in Identity and Access Management with a focus on architecting enterprise OAuth and SAML solutions for authentication and authorization throughout distributed systems. With a passion for OAuth in particular, he has spent much of his time seeking out and mitigating vulnerabilities from misimplemented OAuth solutions and contributed to the open source Rails OAuth provider, Doorkeeper. His passion for securing web applications has prompted his recent move from IAM to security.

Food: Tacodeli. PLEASE RSVP ahead of time so we can be sure to have enough for all! Arriving at 11:30 AM gives you time to get some food and find a seat. We try to start the meeting around 11:50 AM

Only those who RSVP will be eligible for any drawings/giveaways that may take place!

RSVP: https://owasp-austin-2019-september.eventbrite.com

Or if you can not attend we should be broadcasting the meeting via Zoom: https://zoom.us/j/913160162

NOTE: This will be our last chapter meeting of the year. Our next one will be in January. Of course we hope to see you all next month at LASCON. https://lascon.org

Back to Top

LASCON X

When: Tuesday & Wednesday, October 22-23, 2019 (Pre-Conference Training), Thursday & Friday, October 24-25, 2019 (Conference Sessions)

Where: Norris Conference Center, 2525 W. Anderson Lane, Suite 365, Austin, Texas 78757

What: The Lonestar Application Security Conference (LASCON) is an OWASP conference held annually in Austin, TX. It is a gathering of 400+ web app developers, security engineers, mobile developers and information security professionals. LASCON is held in Texas where more Fortune 500 companies call home than any other state and it is held in Austin which is a hub for startups in the state of Texas. At LASCON, leaders at these companies along with security architects and developers gather to share cutting-edge ideas, initiatives, and technology advancements.

This will be our 10th year anniversary of LASCON. We are getting an early start to create a memorable conference.

Back to Top

How to add a new Austin article

You can follow the instructions to make a new Austin article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the Austin category:

[[Category:Austin]]