This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Los Angeles"
Sarah Baso (talk | contribs) |
|||
Line 5: | Line 5: | ||
===== https://lists.owasp.org/mailman/listinfo/owasp-losangeles ===== | ===== https://lists.owasp.org/mailman/listinfo/owasp-losangeles ===== | ||
− | <paypal>Los Angeles</paypal> | + | <paypal>Los Angeles</paypal> |
− | == Next Chapter Meeting: Wednesday, | + | == Next Chapter Meeting: Wednesday, June 22, 2011 7:00 P.M. - 8:30 P.M. <br> == |
Symantec<br>900 Corporate Pointe<br>Culver City, CA 90232<br> | Symantec<br>900 Corporate Pointe<br>Culver City, CA 90232<br> | ||
− | Please RSVP: http://owasp- | + | Please RSVP: http://owasp-june2011.eventbrite.com/ |
---- | ---- | ||
− | ==== Topic: | + | ==== Topic: Gray, the new Black: Gray-Box Web Vulnerability Testing ==== |
− | + | Penetration testers who use only black-box tools are destined to lose to attackers who are willing to spend more time or effort looking for vulnerabilities. Defenders need to make use of one of the few natural advantages at their disposal: ready access to the system they’re trying to protect. | |
+ | |||
+ | In this talk Brian will discuss gray-box vulnerability testing techniques that expose web application internals so that testers understand what an application is doing and can spot vulnerabilities faster. The tool observes the program while it executes. It reveals attack surface, points out vulnerable program behavior, opens up a code-level view of the application, and allows a tester to understand information flow inside the program. | ||
+ | |||
+ | ==== Speaker: Brian Chess ==== | ||
+ | |||
+ | Brian is currently the Founder/Chief Scientist at Fortify Software, an HP Company. Prior to his work with Fortify, Brian worked at NetSuite, where he started out as a programmer (when the whole company still fit into one apartment) then managed a small team, then a bigger one, then all of the developers, and eventually became the Director of Software Development. Brian has a PhD in Computer Engineering from the University of California, Santa Cruz, and is the co-author of Secure Coding with Static Analysis. | ||
− | |||
− | |||
---- | ---- |
Revision as of 03:00, 31 May 2011
Local News
Sign up for OWASP Los Angeles mailing list, very low volume and spam free.
https://lists.owasp.org/mailman/listinfo/owasp-losangeles
<paypal>Los Angeles</paypal>
Next Chapter Meeting: Wednesday, June 22, 2011 7:00 P.M. - 8:30 P.M.
Symantec
900 Corporate Pointe
Culver City, CA 90232
Please RSVP: http://owasp-june2011.eventbrite.com/
Topic: Gray, the new Black: Gray-Box Web Vulnerability Testing
Penetration testers who use only black-box tools are destined to lose to attackers who are willing to spend more time or effort looking for vulnerabilities. Defenders need to make use of one of the few natural advantages at their disposal: ready access to the system they’re trying to protect.
In this talk Brian will discuss gray-box vulnerability testing techniques that expose web application internals so that testers understand what an application is doing and can spot vulnerabilities faster. The tool observes the program while it executes. It reveals attack surface, points out vulnerable program behavior, opens up a code-level view of the application, and allows a tester to understand information flow inside the program.
Speaker: Brian Chess
Brian is currently the Founder/Chief Scientist at Fortify Software, an HP Company. Prior to his work with Fortify, Brian worked at NetSuite, where he started out as a programmer (when the whole company still fit into one apartment) then managed a small team, then a bigger one, then all of the developers, and eventually became the Director of Software Development. Brian has a PhD in Computer Engineering from the University of California, Santa Cruz, and is the co-author of Secure Coding with Static Analysis.
Would you like to speak at an OWASP Los Angeles Meeting?
Call for Papers (CFP) is NOW OPEN. To speak at upcoming OWASP Los Angeles meetings please submit your BIO and talk abstract via email to Tin Zaw. When we accept your talk, it will be required to use the Powerpoint OWASP Template.
Archives of Previous Meetings
A list of previous presentations conducted at the Los Angeles Chapter can be found here.
Los Angeles Chapter
- Tin Zaw -- Chapter Leader and Chair
- Cassio Goldschmidt -- Board Member
- Richard Greenberg -- Board Member
- Sarah Baso -- Chapter Administrator
The AppSec USA 2010 conference received rave reviews. Thanks to all the volunteers and great speakers who helped make it a success!
Check out the videos: http://vimeo.com/user4863863/videos