Bay Area

NEXT EVENT:

February, 21st @ 6PM - Robert Half International

OWASP Bay Area will host its next meeting at the Robert Half International on Thursday, February 21. As usual attendance is free and food and beverages will be provided. This will be an awesome event and a great opportunity to network with industry peers. The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.

Agenda and Presentations:

6:00pm - 6:30pm ... Check-in and Reception (food & beverages)

6:30pm - 7:15pm ... ''Your Client-Side Security Sucks. Stop Using It.'' – Kurt Grutzmacher

7:15pm - 8:00pm ... NTLM attacks and countermeasures – Eric Rachner

8:00pm - 8:30pm ... Networking Session

Venue: Robert Half International 5720 Stoneridge Dr Pleasanton CA 94588

''Your Client-Side Security Sucks. Stop Using It.''

Presented by: Kurt Grutzmacher

Abstract: Browser-based security has been used for many years to 'protect' back-end systems from attack or to enhance the user experience. This should not be your only protection and can even open your application to business logic flaws that scanning tools can not detect nor report upon! This talk will show some real world examples of client-side security and the failures they introduced. Business logic flaws such as the MacWorld Expo Platinum Pass will be examined in depth.

Bio: Kurt Grutzmacher has been performing Penetration Testing for a "very large financial institution" for nearly a decade and recently moved to a "very large utility company" to start their internal testing program. For two years in a row he has exposed the methods required to obtain free Platinum Passes to MacWorld and is hoping they'll get it right the third time, he's tired of explaining it to them. Kurt contributes to the Metasploit project occasionally and is currently working on enhancing the project's support for NTLM in web-based attacks. He also randomly blogs at http://grutztopia.jingojango.net/ -- very randomly.

NTLM attacks and countermeasures

Presented by: Eric Rachner

Abstract: Coming soon.

Bio: Coming soon.

Please RSVP by responding to this email or visit http://owaspfeb2008.eventbrite.com

Special thanks to Robert Half International for hosting this event and to Cenzic for sponsoring.