Denver

Next Chapter Meeting: RSVP Now!!!
Chapter Meeting April 18th at 6'ish at Hosting. RSVP HERE so we can order the right # of pizzas (Boulder's meeting will be on the 19th in case you can't attend Denver's).

Please bring a laptop with WebScarab & Firefox installed

Hands-on Introduction to WebScarab & WebGoat
Please bring a laptop that has wireless capability with a copy of WebScarab & Firefox installed. Tim Van Cleave will introduce WebScarab and show and tell us how to use it on WebGoat. The content will be geared towards those who have little to no experience using a web proxy or application testing and want to learn. Tim will cover some of the OWASP Top 10 issues to get students started using a proxy and web application security testing. WebScarab Download: http://sourceforge.net/projects/owasp/files/WebScarab/20070504-1631/

Java Download: http://www.oracle.com/technetwork/java/javase/downloads/index.html

[http://dowasp20120418.eventbrite.com/   RSVP Now!!! ] so we can order the right # of pizzas

Future meetings are planned for: May, Jun, July, August, September, and October.

New Chapter Board of Directors!
Here's the team that's putting it all together:
 * Chairman/Chapter Leader - Andy Lewis
 * Vice Chairman - Steve Kosten
 * Communications Chairman - Craig Klosterman
 * Comm Vice-Chair - Alan Darien
 * Outreach & Education Chair - James Synovec
 * Outreach & Education Vice Chair - Brad Carvalho
 * FROC Chair - Kathy Thaxton

NOTE: THIS WIKI IS USUALLY TERRIBLY OUT OF DATE. PLEASE FOLLOW @OWASP303 ON TWITTER AND/OR SUBSCRIBE TO THE MAILING LIST

OWASP Podcast
OWASP Podcast

Denver

Questions, Comments
Questions can be directed to


 * Andy Lewis, Denver OWASP: alewis 'at' owasp.org

Chapter Meetings
Meetings are usually the 3rd Wednesday of the month. We are trying to have at least 2/quarter. If you can't make the Denver meeting, the Boulder meeting is usually the 3rd Thursday of the month.

Future Meetings
SNOWFROC 2012 March 22d at the Tivoli!

[Denver April 2012 meeting] - stay tuned...

Past Meetings
[Denver February 2012 meeting|February 15th 2012: Andy Lewis "Why OWASP? OWASP is the wheel. You don't need to reinvent it!]

[Denver January 2012 meeting January 18th, 2012| Greg Knaddison "How Does Drupal Security Stack up?"

September 14th 2011: Chris Schmidt "OWASP ESAPI"

March 17th 2011: Hands on "Hack a Thon"

September 22nd 2010: Eric Duprey: Application Vulnerability Shooting Gallery

August 18th 2010: Clint Pollock: Protecting Your Applications from Backdoors

June 2nd 2010: Front Range OWASP Conference

January 20th 2010: John Evans: Securing Webapps: An Illustrative Overview

November 18th 2009: Anton Rager: Advanced XSS

August 27th 2009: Jon Rose: Security in the Clouds

May 2009: Dr. Joseph McComb & and Daniel Weiske: Compliance and application security testing

March 2009: Front Range OWASP Conference (SnowFROC)

January 2009: David Campbell & Eric Duprey: Guided Tour: AppSec NYC '08 CTF

October 2008: Alex Smolen: The OWASP ASP .NET ESAPI

September 2008: John Dickson: Black Box vs. White Box: Different App Testing Strategies

August 2008: Dan Cornell: Static Analysis

July 2008: David Byrne & Eric Duprey: Grendel-Scan

June 2008: Front Range OWASP Conference: Jeremiah Grossman, Robert Hansen, and more!

May 2008: David Campbell & Eric Duprey: XSS Attacks & Defenses

April 2008: Ryan Barnett: Virtual Patching with ModSecurity

February 2008: Michael Sutton: SQL Injection Revisited

June 2007

April 2007

February 2007

January 2007

November 2006

Mailing List
Join the OWASP Denver Mailing List to receive meeting notifications via email

Twitter Feed @owasp303
Denver OWASP has created a Twitter feed @owasp303 to keep you in the loop. Whilst the mailing list is primarily intended to be low-traffic and only provide updates regarding the times, locations, and topics for chapter meetings, the Twitter feed will also provide noteworthy appsec updates.

Denver OWASP Chapter Leaders

 * Andy Lewis, Denver OWASP: alewis 'at' owasp.org

Key OWASP Resources

 * http://www.owasp.org/images/4/41/ASVS_One_Page_Handout.pdf
 * http://www.owasp.org/images/3/31/ESAPI_One_Page_Handout.pdf
 * http://www.owasp.org/images/a/a1/Legal_One_Page_Handout.pdf
 * http://www.owasp.org/images/a/a3/How_ESAPI_Works.pdf
 * http://www.owasp.org/images/a/ac/LAMP_Should_be_Spelled_LAMPE.pdf
 * http://www.owasp.org/images/0/01/Getting_started_designing_for_a_level_of_assurance.pdf
 * http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories
 * http://www.owasp.org/index.php/Man_vs._Code
 * http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf
 * http://www.owasp.org/images/c/cd/PHP-ESAPI_1.0a_install.pdf
 * http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf
 * http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf
 * http://www.owasp.org/images/c/cd/PHP-ESAPI_1.0a_install.pdf
 * http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf
 * http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf

Chapter Management Links
Denver OWASP Chapter SOPs

SnowFROC 2012 Schedule Draft