This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "San Jose"

From OWASP
Jump to: navigation, search
(Next Meeting - Tuesday, December 19, 2006)
Line 1: Line 1:
 
{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:[email protected] Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}
 
{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:[email protected] Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}
  
== Next Meeting - Tuesday, December 19, 2006 ==
+
== Next Meeting - Thursday, April 12, 2007 ==
 
Open to the public, attendance is free
 
Open to the public, attendance is free
  
 
'''Agenda and Presentations:'''<br/>
 
'''Agenda and Presentations:'''<br/>
6:00pm 6:30pm ... Check-in and reception (food & bev)<br/>
+
6:00pm - 6:30pm ... Check-in and reception (food & bev)<br/>
6:30pm – 6:45pm ... About OWASP, Brian Bertacini <br/>
+
6:30pm - 7:30pm ... Past, Present and Future of Web Application Security in PCI - Bernie Weidel<br/>
6:45pm – 7:30pm ... Latest Web Application Security Trends and Statistics, Jeremiah Grossman<br/>
+
7:30pm - 8:30pm ... Top Web Application Vulnerabilities, Exploits and Countermeasures - Josh Daymont<br/>
7:30pm 8:30pm ... Networking & Holiday Reception<br/>
 
  
 
'''Venue:'''<br/>
 
'''Venue:'''<br/>
Fujitsu Advanced Networking Solutions<br/>
+
Ariba<br/>
1240 E. Arques Ave.<br/>
+
807 11th Avenue<br/>
Sunnyvale, CA 94085<br/>
+
Sunnyvale, Ca 94089<br/>
 +
[http://www.ariba.com/company/hq_map.cfm Map and Directions]<br/>
  
  
'''New Trends and Web Application Security Statistics'''<br/>
+
'''Past, Present and Future of Web Application Security in PCI'''<br/>
'''''Presented by: Jeremiah Grossman, Founder & CTO, WhiteHat Security'''''<br/>
+
'''''Presented by: Bernie Weidel - PCI Product Manager, Qualys'''''<br/>
  
'''Abstract:''' First Look at New Web Application Security Statistics. The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet. And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.
+
'''Abstract:'''  
 +
This presentation will start off with a holistic view of Ecommerce Data Security in contrast to the overall scope of Fraud in the Financial Services Industry, thereby giving insights as to why the PCI DSS was created by the Credit Card Brands and developed into its current form. Next, we will explore the current state of Web Application Security in the PCI DSS v1.1 and attempt to bring clarity to some of the more confusing items. We will also outline the structure of the PCI DSS Council; reviewing its key concepts and requirements. Lastly, we will outline methods you can use to proactively get involved in shaping future versions of the PCI DSS.<br/>
  
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report. Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.
+
'''Bio:''' Bernie Weidel, Product Manager for QualysGuard PCI is responsible for evaluating customer/partner requirements, integrating them into the product, and driving PCI to market. Bernie has been developing methods to achieve and evidence compliance since 2000, when he designed a HIPAA compliance program for Scarborough Insurance Agency. Prior to joining Qualys, Bernie was an Infrastructure Security Project Manager at Adobe Systems where he implemented, managed and streamlined SOX and PCI compliance programs. He was also responsible for various aspects of security such as Web Application Security, Database Security, PDA Security and Vulnerability Management. Before Adobe, Bernie worked for Symbol Wireless Technologies as a Wireless Systems Analyst; designing, installing and troubleshooting/fine tuning Enterprise Wireless Networks.
 
<br/>
 
<br/>
•    Identify and discuss the top ten vulnerabilities <br/>
+
<br/>
•    Define the severity levels of web application vulnerabilities <br/>
+
<br/>
•    Present strategies for web application vulnerability management <br/>
+
'''Top Web Application Vulnerabilities, Exploits and Countermeasures'''<br/>
 +
'''''Presented by: Josh Daymont - Sr. Security Consultant, Fortify'''''<br/>
 +
 
 +
'''Abstract:'''
 +
This presentation will take a look at Web Application Security from the Front lines to the back offices of systems development. First, a look at the top vulnerabilities and how are they exploited. Then look beyond the front lines and explore countermeasures that can be implemented during the development process to protect applications and sensitive data after deployment.<br/>
 +
 
 +
 
  
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.
 
  
<br/>
 
 
'''About OWASP'''<br/>
 
'''About OWASP'''<br/>
 
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''<br/>
 
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''<br/>

Revision as of 03:52, 2 April 2007

OWASP San Jose

Welcome to the San Jose chapter homepage. The chapter leader is Brian Bertacini


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


Next Meeting - Thursday, April 12, 2007

Open to the public, attendance is free

Agenda and Presentations:
6:00pm - 6:30pm ... Check-in and reception (food & bev)
6:30pm - 7:30pm ... Past, Present and Future of Web Application Security in PCI - Bernie Weidel
7:30pm - 8:30pm ... Top Web Application Vulnerabilities, Exploits and Countermeasures - Josh Daymont

Venue:
Ariba
807 11th Avenue
Sunnyvale, Ca 94089
Map and Directions


Past, Present and Future of Web Application Security in PCI
Presented by: Bernie Weidel - PCI Product Manager, Qualys

Abstract: This presentation will start off with a holistic view of Ecommerce Data Security in contrast to the overall scope of Fraud in the Financial Services Industry, thereby giving insights as to why the PCI DSS was created by the Credit Card Brands and developed into its current form. Next, we will explore the current state of Web Application Security in the PCI DSS v1.1 and attempt to bring clarity to some of the more confusing items. We will also outline the structure of the PCI DSS Council; reviewing its key concepts and requirements. Lastly, we will outline methods you can use to proactively get involved in shaping future versions of the PCI DSS.

Bio: Bernie Weidel, Product Manager for QualysGuard PCI is responsible for evaluating customer/partner requirements, integrating them into the product, and driving PCI to market. Bernie has been developing methods to achieve and evidence compliance since 2000, when he designed a HIPAA compliance program for Scarborough Insurance Agency. Prior to joining Qualys, Bernie was an Infrastructure Security Project Manager at Adobe Systems where he implemented, managed and streamlined SOX and PCI compliance programs. He was also responsible for various aspects of security such as Web Application Security, Database Security, PDA Security and Vulnerability Management. Before Adobe, Bernie worked for Symbol Wireless Technologies as a Wireless Systems Analyst; designing, installing and troubleshooting/fine tuning Enterprise Wireless Networks.


Top Web Application Vulnerabilities, Exploits and Countermeasures
Presented by: Josh Daymont - Sr. Security Consultant, Fortify

Abstract: This presentation will take a look at Web Application Security from the Front lines to the back offices of systems development. First, a look at the top vulnerabilities and how are they exploited. Then look beyond the front lines and explore countermeasures that can be implemented during the development process to protect applications and sensitive data after deployment.



About OWASP
Presented by: Brian Bertacini, Volunteer chapter organizer

Abstract: An overview of the Open Web Application Security Project (OWASP), current projects and feedback from the recent WebAppSec Conference in Seattle.

Please RSVP to via email Brian Bertacini, call 408-979-0571 or visit OWASP.Mollyguard.com

Special thanks to Fujitsu Advanced Networking Solutions for hosting this event.