Difference between revisions of "8th OWASP IL chapter meeting"

From OWASP
Jump to: navigation, search
(At Watchfire, Herzliya, Wednesday, September 5th 2007, 17:00)
(At Watchfire, Herzliya, Wednesday, September 5th 2007, 17:00)
Line 18: Line 18:
  
  
<big>'''15:10 – 15:40 Evasive Crimeware attacks, Business Risk, and Proposed Defense'''</big>
+
<big>'''15:10 – 15:40 Evasive Crimeware attacks, Business drivers, and Proposed Defense'''</big>
  
 
Iftach Amit, Director Security Research, Finjan
 
Iftach Amit, Director Security Research, Finjan
  
The presentation will explore the “other side” of web security: the client side. As traditional web application security is starting to pay more attention to the client side, which became a major part of the web application security market (can you spell XSS without a client involved…), more and more attack vectors are re-targeting the browser as a way to get into the organization.
+
Any web based attack requires a business model in order to spread. As the director of research for Finjan, Iftach monitors the highly succesful client based web attack vectors and the community that creates tham. In the presentation Iftach will explore advanced browser based attack vectors beyond your day to day XSS.
  
In the presentation we will understand the business risks that are imposed by browsing, explore some recent examples of these attacks with an eye-opening review of the attacker “community” and how it operates (technically and economically). To conclude, the technical aspects of these attacks will be examined in light of the security mechanisms currently available to counteract the attacks, and a short discussion on how to handle the more sophisticated attacks will conclude the presentation.
+
The presentation will cover the business drivers of client side attack vectors, explore recent examples of such attacks with an eye-opening review of the attacker community and its operation methods, and conclude with a technical discussion of the cat and mouse game between cutting edge solutions and ever advancing attack vectors.

Revision as of 02:37, 20 August 2007

At Watchfire, Herzliya, Wednesday, September 5th 2007, 17:00

OWASP IL global security week logo.jpg
The next meeting of OWASP IL, The Israeli Chapter of OWASP, would be held at Watchfire offices in Herzelia on Wed, September 5th at 17:00. Watchfire will also sponsore the meeting. The meeting is part of OWASP Day, a Worldwide OWASP 1 day conferences on Privacy in the 21st Century which is in turn OWASP contribution to the [Global Security Week].

The agenda of the meeting is:


17:00 – 17:15 Gathering and refreshments


15:10 – 15:40 Straight from Blackhat: Dangling Poniters

OWASP IL Sponsor Watchfire.jpg
Jonathan Afek, Senior Security Researcher, Watchfire

Jonthan will bring to us his acclaimed BlackHat presentation. Danglig pointers are a common programming error, but even OWASP assumes that this can lead only to crashes and therefore only to denaial of service attacks (see [OWASP vulnerability guide]. The research team at Watchfire proved that danging pointers can be exploited to take control of the vulnerable system, elivating the severity of dangling pointers.

The presentation will explain the vulnerabity and demonstrate a real exploit of the vulnerability using vulnerability in IIS as an example.


15:10 – 15:40 Evasive Crimeware attacks, Business drivers, and Proposed Defense

Iftach Amit, Director Security Research, Finjan

Any web based attack requires a business model in order to spread. As the director of research for Finjan, Iftach monitors the highly succesful client based web attack vectors and the community that creates tham. In the presentation Iftach will explore advanced browser based attack vectors beyond your day to day XSS.

The presentation will cover the business drivers of client side attack vectors, explore recent examples of such attacks with an eye-opening review of the attacker community and its operation methods, and conclude with a technical discussion of the cat and mouse game between cutting edge solutions and ever advancing attack vectors.