Virginia

Last Month
We had some good talks on 8 March:

"8 Dirty Secrets of IA", Bruce Potter from Booz Allen.

"Web Services Hacking and Hardening", Adam Vincent from Layer 7.

Next Meeting
Our next meeting will be on 19 April, at 6pm. This meeting will be held at Cigital in Sterling.

Zed Abbadi from PCAOB will speak on "Security Metrics: What can we measure?". Zed Abbadi is a senior application security engineer with the Public Company Accounting Oversight Board. He has over 15 years of experience in software and security engineering. His background covers security consulting, software engineering and security research. He has been a regular participant of our chapter meetings.

Dmytro Tomilovskiy from Cigital will talk about second-order XSS with AJAX. Introduction will include a quick overview AJAX, how it works, where it is used and a list of new security concerns that arise from usage of AJAX. He will then talk about one problem from that list – persistent XSS. He will have a few possible scenarios (different architectures) and what remediation strategies are suitable for each scenario.

Pizza and drinks will be provided for a small fee.

Directions
For 19 April, Cigital will host in their Sterling office. For directions, go to

http://www.cigital.com/about/contact.php#directions-corp

- To Booz Allen's One Dulles facility:

13200 Woodland Park Road Herndon, VA 20171

From Tyson's Corner:

1. Take LEESBURG PIKE / VA-7 WEST 2. Merge onto VA-267 WEST / DULLES TOLL ROAD (Portions Toll) 3. Take the VA-657 Exit (Exit Number 10 towards Herndon / Chantilly) 4. Take the ramp toward CHANTILLY 5. Turn Left onto CENTERVILLE ROAD (at end of ramp) 6. Turn Left onto WOODLAND PARK ROAD (less than 1⁄2 mile) 7. End at 13200 WOODLAND PARK ROAD