Denver

Front Range OWASP Conference (FROC 2010)
FROC 2010 was a sellout success! Thanks for your support. The survey results are now posted.

Next Chapter Meeting
WOOT

OWASP Podcast
OWASP Podcast

Denver

Questions, Comments
Questions can be directed to


 * David Campbell, Denver OWASP: dcampbell 'at' owasp.org
 * Eric Duprey, Denver OWASP: eduprey 'at' exploits.org

Future Meetings
TBD

We have had several people ask that our next chapter meeting be a walkthrough of the FROC2010 CTF. We are looking at Wed, 21 July 2010 for this event in a new location near downtown Denver (though with free parking!).

We are also looking at doing a static analysis working group. Due to the hype surrounding the recent adoption of Drupal by the White House and the row that ensued when an XSS flaw was found recently, OWASP is keen to help.

Our friends at Fortify Software and a local OWASP'er who is also a member of the Drupal Security team have proposed that our next meeting be a half day working session to perform static analysis and verification on Drupal.

Interested? Let us know. Tweet with hashtag #owasp303 or email us at froc@owasp.org.

Past Meetings
June 2nd 2010: Front Range OWASP Conference

January 20th 2010: John Evans: Securing Webapps: An Illustrative Overview

November 18th 2009: Anton Rager: Advanced XSS

August 27th 2009: Jon Rose: Security in the Clouds

May 2009: Dr. Joseph McComb & and Daniel Weiske: Compliance and application security testing

March 2009: Front Range OWASP Conference (SnowFROC)

January 2009: David Campbell & Eric Duprey: Guided Tour: AppSec NYC '08 CTF

October 2008: Alex Smolen: The OWASP ASP .NET ESAPI

September 2008: John Dickson: Black Box vs. White Box: Different App Testing Strategies

August 2008: Dan Cornell: Static Analysis

July 2008: David Byrne & Eric Duprey: Grendel-Scan

June 2008: Front Range OWASP Conference: Jeremiah Grossman, Robert Hansen, and more!

May 2008: David Campbell & Eric Duprey: XSS Attacks & Defenses

April 2008: Ryan Barnett: Virtual Patching with ModSecurity

February 2008: Michael Sutton: SQL Injection Revisited

June 2007

April 2007

February 2007

January 2007

November 2006

Mailing List
Join the OWASP Denver Mailing List to receive meeting notifications via email

Twitter Feed @owasp303
Denver OWASP has created a Twitter feed @owasp303 to keep you in the loop. Whilst the mailing list is primarily intended to be low-traffic and only provide updates regarding the times, locations, and topics for chapter meetings, the Twitter feed will also provide noteworthy appsec updates.

Denver OWASP Chapter Leaders

 * David Campbell, Denver OWASP: dcampbell 'at' owasp.org
 * Eric Duprey, Denver OWASP: eduprey 'at' exploits.org

Key OWASP Resources

 * http://www.owasp.org/images/4/41/ASVS_One_Page_Handout.pdf
 * http://www.owasp.org/images/3/31/ESAPI_One_Page_Handout.pdf
 * http://www.owasp.org/images/a/a1/Legal_One_Page_Handout.pdf
 * http://www.owasp.org/images/a/a3/How_ESAPI_Works.pdf
 * http://www.owasp.org/images/a/ac/LAMP_Should_be_Spelled_LAMPE.pdf
 * http://www.owasp.org/images/0/01/Getting_started_designing_for_a_level_of_assurance.pdf
 * http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories
 * http://www.owasp.org/index.php/Man_vs._Code
 * http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf
 * http://www.owasp.org/images/c/cd/PHP-ESAPI_1.0a_install.pdf
 * http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf
 * http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf
 * http://www.owasp.org/images/c/cd/PHP-ESAPI_1.0a_install.pdf
 * http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf
 * http://www.owasp.org/images/6/67/PHP-ESAPI_1.0a_ReleaseNotes.pdf

Chapter Management Links
Best pizza in Centennial