This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

OWASP Day

From OWASP
Revision as of 01:49, 31 August 2007 by Dinis.cruz (talk | contribs) (Proposed Event layout)

Jump to: navigation, search

OWASP Day : Worldwide OWASP chapter meetings on the topic "Privacy in the 21st Century" (5th till 12th October 2007)

OWASP Day is the title given to the 17 chapter meetings (hosted by 19 OWASP Chapters) staged during the Global Security Week.

Global Agenda (19 Chapters participating)

  • Wed 5th
    • Israel (16:45 / 19:30)
      • "Straight from Blackhat: Dangling Pointers" , Jonathan Afek , Watchfire
      • "Evasive Crimeware attacks, Business drivers, and Proposed Defense" , ftach Amit , Finjan
      • "Content Injection as a solution for client side browser vulnerabilities" , Ofer Shezaf , Breach Security (Israel chapter Leader)
    • London (18:30 / 21:30)
      • "For my next trick... hacking Web2.0", Petko D. Petkov (pdp), GNUCITIZEN
      • Panel: "Privacy in the 21st Century?", moderator: Ivan Ristic
      • Panel: "Future of the OWASP London Chapter"
  • Thu 6th
    • NYNJMetro (17:30 / 21:00)
      • "Financial Real-Time Threats: Impacting Trading Floor Operations" , ,
      • "JBroFuzz: Effective Fuzzing for Network and Web Applications" , Dr. Yiannis Pavlosoglou , Information Risk Management
      • "Stock fluctuation from an unrecognized influence" , Justine Bone-Aitel - Immunity Security
      • "Hackers...BotNets oh My! Obtain a briefing on the current BotNet investigations etc.", NYC FBI Cyber Crime Unit
      • "Why today's vulnerability assessments are failing and a case for industry standardization"
      • "Blackhat/Defcon", Tom Brennan (President OWASP NY/NJ Metro)
      • Panel: "Global Security Week What is the current state of Privacy on Web Application Security? What should we be focusing on?"
    • Belgium (12:30 / 19:30)
      • pre-event: "Getting started with WebGoat & WebScarab" ,Erwin Geirnaert , ZION Security
      • "OWASP Evaluation and Certification Criteria Draft" , Mark Curphey (OWASP founder)
      • "Automated Web FOO or FUD?" , David Kierznowski, GNUCITIZEN
      • "OWASP Pantera Unleashed" , Simon Roses Femerling , Microsoft
      • "CLASP, SDL and Touchpoints Compared" , Bart De Win, DistriNet research group
      • "Threats of e-insecurity in Belgium and the Belgian response" , Luc Beirens, FCCU
      • "For my next trick... hacking Web2.0 (pdp)" , Petko D. Petkov (pdp), GNUCITIZEN
      • "Panel Discussion: “Privacy in the 21st Century?", moderator: André Marien , Verizon Business - Cybertrust
    • Washington DC + Northern VA (13:00 / 18:15)
      • "Honeyclients and Malicious Web Servers" , Kathy Wang , Mitre
      • "A malcode perspective on web application privacy" Blake Hartstein , iDefense
      • "Practical Web Privacy with Firefox" , Chuck Willis , Mandiant
      • "A sneak peak at Jeff's new "Enterprise Security API" , Jeff Williams , Aspect Security (OWASP board member & Chairman)
      • "Digital Rights Management" , James Stibbards , Cloakware
    • San Antonio (11:30 / 13:00)
      • "Developing an Application Security Strategy for Large Enterprise Systems" , Bruce Jenkins, Fortify Software
    • Seattle (18:00 / 21:00)
      • "Online Banking" , Rob Rachwald , Fortify
      • "Web Hacking 101", Damon Cortesi , IOActive
    • San Jose + San Francisco (17:00 / 20:30)
      • Workshop: "Malicious Code Injection Workshop" , Siva Ram , AppSec Consulting ; Arian Evans ,WhiteHat Security
      • Panel: "Privacy, Security and Breaches, Oh My!", moderator: Alex Stamos, iSEC Partners ; Panelists: Doran Rotman, KPMG ; David Pollino, Washington Mutual Bank ; Robert Fly, Salesforce.com ; Larry Pingree, Safeway ; Kurt Opsahl, EFF
    • Mumbai (14:30 / 18:00)
      • "Black Vector of Web Exploitation" , Aditya Sood , Sec Niche
      • "End User Privacy Breaches" Rishi Narang , ThirdBrigade"
      • "Privacy on the Web - The road ahead in the 21st century" , Yogesh Badwe , GTL
    • Phoenix
      • TBA
    • Poland
      • TBA
    • Boston
      • TBA
  • Mon 10th
    • Italy (9:00 / 13:30)
      • "Privacy in the digital era" , Mauro Bregolin , KIMA Projects & Services
      • "OWASP Top 10 2007 - Are our information 'really' safe?" , Carlo Pelliccioni , MediaService
      • "Anti-Anti-XSS: bypass browser protections" , Alberto Revelli , Portcullis
      • "Growing Application Security Awareness" , Laurent Petroque , F5
      • "Buzzwords Security" , Luca Carettoni , SecureNetwork
      • "Hacker Attacks on the Horizon: Understanding the Top Web 2.0 Attack Vectors" , Danny Allan , Watchfire
    • Rochester
      • TBA
  • Mon 12th
    • Houston (17:30 / 19:30)
      • "Enhancing Application Security with Bytecode Instrumentation" , Patrick White , Fortify Software
    • Cleveland
      • "The new OWASP Top Ten."

Note: If you are interested in doing a presentation, the following chapters have speaker slots available: Rochester, Boston, Phoenix, Poland and Turkey


Organizers

In addition to the local chapter leaders, Dinis Cruz and Mike de Libero are the main points of contact (but of course much more help is needed :) )


Global Security Week (GWS)

For more details on the (GWS) see:

And here is a description from one the organizers:

The aim of Global Security Week is to raise security awareness amongst the public and organizations about issues relating to security, primarily information security. This year's theme is on the subject of privacy and we hope that a number of events will be held worldwide to promote people's awareness as to how to protect their privacy when online and also educate companies on their responsibilities, both legal and morally, when it comes to protecting the privacy of their customers. Global Security Week is a totally voluntary initiative and we have no commercial funding or agenda. The initiative is funded entirely from the committee's own funds and time. We have people involved in Global Security Week throughout the world and during the week we have events planned in different regions. For example here in Ireland I plan to run a free seminar on the above topic open to anyone who wished to attend

We ask that those who wish to become involved, help promote Global Security Week in their region either by running specific events dedicated to Global Security Week, taking part in events already planned or simply making people aware that the week is on and the topic is "Privacy in the 21st Century". Even simply making people aware of Global Security Week and directing them to the website is a great help. Not having commercial funding we depend on word of mouth and like minded individuals to make people aware of the week.

Other Ideas

  • Create a Security Manifest that will be 'signed' by all attendees
  • Distributed capture the flag (where each local chapter plays has a team (against the other chapters))
  • Short intro/welcome movie at the beginning of each mini-conference by OWASP board