Difference between revisions of "AppSecEU2013"

From OWASP
Jump to: navigation, search
(Thursday 22. August)
m
(17 intermediate revisions by 3 users not shown)
Line 14: Line 14:
 
== Presentations ==
 
== Presentations ==
 
=== Videos ===
 
=== Videos ===
Videos from the talks are available here for [https://www.its.fh-muenster.de/owasp-appseceu13/rooms/Grosser_Saal/ Großer Saal]  
+
Videos from the talks are available for [https://www.its.fh-muenster.de/owasp-appseceu13/rooms/Grosser_Saal/ Großer Saal]  
 
and [https://www.its.fh-muenster.de/owasp-appseceu13/rooms/Aussichtsreich_+_Freiraum/ Aussichtsreich + Freiraum].
 
and [https://www.its.fh-muenster.de/owasp-appseceu13/rooms/Aussichtsreich_+_Freiraum/ Aussichtsreich + Freiraum].
 
=== Slides ===
 
=== Slides ===
 
Quick links to the presentations. All slides are under [http://creativecommons.org/licenses/by-sa/3.0/ CC-BY-SA] license.
 
Quick links to the presentations. All slides are under [http://creativecommons.org/licenses/by-sa/3.0/ CC-BY-SA] license.
  
==== Thursday 22. August ====
+
==== Thursday, August 22nd ====
 
* [[Media:Welcome_Note_-_Dirk_Wetter.pdf|Welcome Note]]; Dirk Wetter
 
* [[Media:Welcome_Note_-_Dirk_Wetter.pdf|Welcome Note]]; Dirk Wetter
* [[Media:--coming soon--|Busting The Myth of Dancing Pigs: Angela's Top 10 list of reasons why users bypass security measures]]
+
* Keynote: [[Media:OWASP_angela_sasse_appsec_eu_aug2013.pdf|Busting The Myth of Dancing Pigs: Angela's Top 10 list of reasons why users bypass security measures]]; Angela Sasse
* [[Media:OWASP_Where_we_are.._Where_we_are_going.pdf|OWASP Where we are.. Where we are going]]
+
* [[Media:OWASP_Where_we_are.._Where_we_are_going.pdf|OWASP: Where we are... Where we are going]]
 
* [[Media:A Qualitative Comparison of SSL Validation Alternatives - Henning Perl+Michael Brenner+Mathew Smith.pdf|A Qualitative Comparison of SSL Validation Alternatives]]; Henning Perl, Michael Brenner
 
* [[Media:A Qualitative Comparison of SSL Validation Alternatives - Henning Perl+Michael Brenner+Mathew Smith.pdf|A Qualitative Comparison of SSL Validation Alternatives]]; Henning Perl, Michael Brenner
 
* [[Media:Recipes_for_enabling_HTTPS_-_Thomas_Herlea+Neils_Boucke+Johann_Peeters.pdf|Recipes for enabling HTTPS]]; Thomas Herlea, Neils Boucke, Johann Peeters
 
* [[Media:Recipes_for_enabling_HTTPS_-_Thomas_Herlea+Neils_Boucke+Johann_Peeters.pdf|Recipes for enabling HTTPS]]; Thomas Herlea, Neils Boucke, Johann Peeters
Line 30: Line 30:
 
* [[Media:Improving_the_Security_of_Session_Management_in_Web_Applications_-_Philippe_De_Ryck.pdf|Improving the Security of Session Management in Web Applications]];  Philippe DeRyck
 
* [[Media:Improving_the_Security_of_Session_Management_in_Web_Applications_-_Philippe_De_Ryck.pdf|Improving the Security of Session Management in Web Applications]];  Philippe DeRyck
 
* [[Media:A_Doorman_for_Your_Home--Control-Flow_Integrity_Means_in_Web_Frameworks_-_Bastian_Brown.pdf|A Doorman for Your Home - Control-Flow Integrity Means in Web Frameworks]]; Bastian Braun
 
* [[Media:A_Doorman_for_Your_Home--Control-Flow_Integrity_Means_in_Web_Frameworks_-_Bastian_Brown.pdf|A Doorman for Your Home - Control-Flow Integrity Means in Web Frameworks]]; Bastian Braun
 
+
* [[Media:Technical_Due_Diligence_-_Amir_Alsbih.pdf|Experience made in Technical Due Diligence]]; Amir Alsbih
* [[Media:Technical_Due_Diligence_-_Amir_Alsbih.pdf|Experiance made in Technical Due Diligence]]; Amir Alsbih
+
 
* [[Media:OWASP-CISO_Guide_and_CISO_report_2013_for_managers_-_Tobias_Gondrom.pdf|OWASP - CISO Guide and CISO report 2013 for managers]]; Tobias Gondrom
 
* [[Media:OWASP-CISO_Guide_and_CISO_report_2013_for_managers_-_Tobias_Gondrom.pdf|OWASP - CISO Guide and CISO report 2013 for managers]]; Tobias Gondrom
 
* [[Media:Real World Agile SDLC - Chris Eng+Ryan OBoyle.pdf|Real World Agile SDLC]]; Chris Eng, Ryan O'Boyle
 
* [[Media:Real World Agile SDLC - Chris Eng+Ryan OBoyle.pdf|Real World Agile SDLC]]; Chris Eng, Ryan O'Boyle
* [[Media:OWASP Top 10 Proactive Controls.pdf]]; Jim Manico
+
* OWASP Top 10 Proactive Controls; Jim Manico (external link: presentation done by Jason Johnson at http://prezi.com/_oug648-i4yr/owasp-top-ten-defenses )
 
* [[Media:CSP--the_panacea_for_XSS_or_placebo_-_Taras_Ivashchenko.pdf‎|CSP - the panacea for XSS or placebo]]; Taras Ivashchenko
 
* [[Media:CSP--the_panacea_for_XSS_or_placebo_-_Taras_Ivashchenko.pdf‎|CSP - the panacea for XSS or placebo]]; Taras Ivashchenko
* [[Media:Security_Testing_Guidelines_for_mobile_Apps_-_Florian_Stahl+Johannes_Stroeher.pdf|Security_Testing_Guidelines_for_mobile_Apps]]; Florian_Stahl, Johannes Stroeher
+
* [[Media:Security_Testing_Guidelines_for_mobile_Apps_-_Florian_Stahl+Johannes_Stroeher.pdf|Security Testing Guidelines for mobile Apps]]; Florian_Stahl, Johannes Stroeher
 
+
* [[Media:HTML5--ALL_THE_THINGS_-_Thomas_Roessler.pdf|HTML5 - ALL THE THINGS]]; Thomas Roessler
+
  
 +
* Keynote: HackPra Allstars [[Media:]]; Jörg Schwenk
 
* HackPra Allstars [[Media:HackPraAllstars_Rooting_Your_Internals_-_Michele_Orru.pdf|Rooting Your Internals]]; Michele Orru
 
* HackPra Allstars [[Media:HackPraAllstars_Rooting_Your_Internals_-_Michele_Orru.pdf|Rooting Your Internals]]; Michele Orru
<!--
 
* HackPra Allstars [[Media:--comming soon--]]; Jörg Schwenk
 
* HackPra Allstars [[Media:--comming soon--]]; Paul Stone
 
-->
 
 
* HackPra Allstars [[Media:HackPra_Allstars-Burp_Pro_Tips_and_Tricks_-_Nicolas_Grégoire.pdf|Burp Pro Tips and Tricks]]; Nicolas Grégoire
 
* HackPra Allstars [[Media:HackPra_Allstars-Burp_Pro_Tips_and_Tricks_-_Nicolas_Grégoire.pdf|Burp Pro Tips and Tricks]]; Nicolas Grégoire
 
* HackPra Allstars [[Media:HackPra_Allstars-Augmented_Reality_in_your_web_proxy_-_Roberto_Suggi_Liverani.pdf‎|Augmented Reality in your web proxy]]; Roberto Suggi Liverani
 
* HackPra Allstars [[Media:HackPra_Allstars-Augmented_Reality_in_your_web_proxy_-_Roberto_Suggi_Liverani.pdf‎|Augmented Reality in your web proxy]]; Roberto Suggi Liverani
<!--
+
* HackPra Allstars: Browser Timing Attacks [http://contextis.co.uk/files/Browser_Timing_Attacks.pdf| (Paper)]; Paul Stone
 +
 
 +
<!-- Slides entsprechen nicht dem Speakers Agreement
 +
 
 
* HackPra Allstars [[Media:--comming soon--]]; Gareth Heyes
 
* HackPra Allstars [[Media:--comming soon--]]; Gareth Heyes
 
* HackPra Allstars [[Media:--comming soon--]]; Eduardo Vela
 
* HackPra Allstars [[Media:--comming soon--]]; Eduardo Vela
Line 63: Line 60:
 
-->
 
-->
  
==== Friday 23. August ====
+
==== Friday August, 23rd ====
<!-- * [[Media:--comming soon--]]; Nick Nikiforakis -->
+
* Keynote: [[Media:HTML5--ALL_THE_THINGS_-_Thomas_Roessler.pdf|Secure all the things: fiction from the Web’s immediate future]]; Thomas Roessler
 +
* [[Media:OWASP_AppSec_Research_2013_-_Webfingerprinting.pdf|Web Fingerprinting: How, who and why?]]; Nick Nikiforakis  
 
* [[Media:Making_the_Future_Secure_with_Java_-_Milton_Smith.pdf‎|Making the Future Secure with Java]]; Milton Smith
 
* [[Media:Making_the_Future_Secure_with_Java_-_Milton_Smith.pdf‎|Making the Future Secure with Java]]; Milton Smith
 
* [[Media:OWASP_Top-10_2013--AppSec_EU_2013_-_Dave_Wichers.pdf|OWASP Top-10 2013]]; Dave Wichers
 
* [[Media:OWASP_Top-10_2013--AppSec_EU_2013_-_Dave_Wichers.pdf|OWASP Top-10 2013]]; Dave Wichers
Line 71: Line 69:
 
* [[Media:OWASP_AppSensor--In_Theory,_In_Practice_and_In_Print_-_Colin_Watson.pdf|OWASP AppSensor - In Theory, In Practice and In Print]]; Colin Watson
 
* [[Media:OWASP_AppSensor--In_Theory,_In_Practice_and_In_Print_-_Colin_Watson.pdf|OWASP AppSensor - In Theory, In Practice and In Print]]; Colin Watson
 
* [[Media:Introducing_ASVS_2013_-_Sahba_Kazerooni+Daniel_Cuthbert.pdf|Introducing ASVS 2013]]; Sahba Kazerooni, Daniel Cuthbert
 
* [[Media:Introducing_ASVS_2013_-_Sahba_Kazerooni+Daniel_Cuthbert.pdf|Introducing ASVS 2013]]; Sahba Kazerooni, Daniel Cuthbert
 
+
<!-- Slides entsprechen nicht dem Speakers Agreement
 
* [[Media:--comming soon--]]; Erlend Oftedal
 
* [[Media:--comming soon--]]; Erlend Oftedal
 +
-->
 
* [[Media:Insane_in_the_IFRAME_-_David_Ross.pdf|Insane in the IFRAME]]; David Ross
 
* [[Media:Insane_in_the_IFRAME_-_David_Ross.pdf|Insane in the IFRAME]]; David Ross
 
* [[Media:JS_Libraries_Insecurity_-_Stefano_DiPaola.pdf|JS Libraries Insecurity]]; Stefano DiPaola
 
* [[Media:JS_Libraries_Insecurity_-_Stefano_DiPaola.pdf|JS Libraries Insecurity]]; Stefano DiPaola
Line 79: Line 78:
 
* [[Media:I_am_in_your_browser,_pwning_your_stuff_-_Krzysztof_Kotowicz.pdf‎|I am in your browser, pwning your stuff]]; Krzysztof Kotowicz
 
* [[Media:I_am_in_your_browser,_pwning_your_stuff_-_Krzysztof_Kotowicz.pdf‎|I am in your browser, pwning your stuff]]; Krzysztof Kotowicz
 
* [[Media:Sandboxing-Javascript_-_Lieven_Desmet+Nick_Nikiforakis.pdf|Sandboxing Javascript]]; Lieven Desmet, Nick Nikiforakis
 
* [[Media:Sandboxing-Javascript_-_Lieven_Desmet+Nick_Nikiforakis.pdf|Sandboxing Javascript]]; Lieven Desmet, Nick Nikiforakis
 
+
* [[Media:RaspberryPi_for_the_Infrasturcture_and_hacker_-_Fred_Donavan.pdf|RaspberryPi for the Infrastructure and hacker]]; Fred Donavan
* [[Media:RaspberryPi_for_the_Infrasturcture_and_hacker_-_Fred_Donavan.pdf|RaspberryPi for the Infrasturcture and hacker]]; Fred Donavan
+
* [[Media:Minion--Making Security Accessible for Developers - Yvan Boily.tar|Minion - Making Security Accessible for Developers]]; Yvan Boily (download tar and open index.html in your browser; all sources are [https://github.com/ygjb/appsec-eu-2013 here])
* [[Media:--comming soon--]]; Yvan Boily
+
 
* [[Media:ZAP_Innovations_-_Simon_Benetts.pdf|ZAP Innovations]]; Simon Benetts
 
* [[Media:ZAP_Innovations_-_Simon_Benetts.pdf|ZAP Innovations]]; Simon Benetts
 
* [[Media:Do_You_Have_a_Scanner_or_Scanning_Program_-_Dan_Cornell.pdf‎|Do_You_Have a Scanner or Scanning Program]]; Dan Cornell
 
* [[Media:Do_You_Have_a_Scanner_or_Scanning_Program_-_Dan_Cornell.pdf‎|Do_You_Have a Scanner or Scanning Program]]; Dan Cornell
 
* [[Media:OWTF--Summer_StormShort_-_Abraham_Aranguren.pdf|OWTF  Summer StormShort]]; Abraham Aranguren
 
* [[Media:OWTF--Summer_StormShort_-_Abraham_Aranguren.pdf|OWTF  Summer StormShort]]; Abraham Aranguren
 +
* [[Media:OWASP_Hackademic_Challenges_-_Konstantinos_Papapanagiotou+Spyros_Gasteratos.pdf|OWASP Hackademic Challenges]]; Konstantinos Papapanagiotou
 
* [[Media:SPaCIoS_-_Luca_Compagna.pdf|SPaCIoS]]; Luca Viganò, Luca Compagna
 
* [[Media:SPaCIoS_-_Luca_Compagna.pdf|SPaCIoS]]; Luca Viganò, Luca Compagna
* OSS [[Media:OWASP_Hackademic_Challenges_-_Konstantinos_Papapanagiotou+Spyros_Gasteratos.pdf|OWASP Hackademic Challenges]]; Konstantinos Papapanagiotou
 
 
<!--
 
<!--
 
* OSS [[Media:]]; Dinis Cruz
 
* OSS [[Media:]]; Dinis Cruz
 
* OSS [[Media:]]; Juray Somorowsky
 
* OSS [[Media:]]; Juray Somorowsky
 
-->
 
-->
* [[Media:Closing_Note_-_Dieter_Gollmann.pdf‎|Closing Note]]; Dieter Gollmann
+
* Closing Note: [[Media:Closing_Note_-_Dieter_Gollmann.pdf‎|Access Control of the Web – The Web of Access Control]]; Dieter Gollmann
 
* [[Media:Closing-Ceremony_-_Dirk_Wetter.pdf‎|Closing Ceremony]]; Dirk Wetter
 
* [[Media:Closing-Ceremony_-_Dirk_Wetter.pdf‎|Closing Ceremony]]; Dirk Wetter
  
Line 98: Line 96:
 
The <u>[[Germany|German OWASP Chapter]]</u> is hosting the global OWASP AppSec Research 2013 conference in <u>[http://en.wikipedia.org/wiki/Hamburg Hamburg]</u>, Germany from August 20-23. Hamburg is the second biggest city in Germany, <u>[https://maps.google.com/maps?q=Hamburg,+Germany&hl=en&ll=51.426614,10.239258&spn=12.838461,14.589844&sll=37.0625,-95.677068&sspn=61.799062,58.359375&oq=hamburg&hnear=Hamburg,+Germany&t=m&z=6 located in the north]</u>. To quote New York Times: <u>[http://travel.nytimes.com/2012/01/22/travel/36-hours-hamburg-germany.html No one tells you how pretty Hamburg is]</u>. We do.  
 
The <u>[[Germany|German OWASP Chapter]]</u> is hosting the global OWASP AppSec Research 2013 conference in <u>[http://en.wikipedia.org/wiki/Hamburg Hamburg]</u>, Germany from August 20-23. Hamburg is the second biggest city in Germany, <u>[https://maps.google.com/maps?q=Hamburg,+Germany&hl=en&ll=51.426614,10.239258&spn=12.838461,14.589844&sll=37.0625,-95.677068&sspn=61.799062,58.359375&oq=hamburg&hnear=Hamburg,+Germany&t=m&z=6 located in the north]</u>. To quote New York Times: <u>[http://travel.nytimes.com/2012/01/22/travel/36-hours-hamburg-germany.html No one tells you how pretty Hamburg is]</u>. We do.  
  
The AppSec Research conference will be a premier gathering of Information Security leaders, also it is going to have a research part.
+
The AppSec Research conference will be a premier gathering of Information Security leaders, also it has a research part.
  
 
Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 400-500 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology and many other verticals.  
 
Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 400-500 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology and many other verticals.  
Line 172: Line 170:
 
:[[User:Dirk Wetter|Dirk Wetter]] (Chair)
 
:[[User:Dirk Wetter|Dirk Wetter]] (Chair)
 
:[[User:Kai Jendrian|Kai Jendrian]] (Co-Chair)
 
:[[User:Kai Jendrian|Kai Jendrian]] (Co-Chair)
:Birgit Bernskötter (External)
 
 
:[[User:Ingo Hanke|Ingo Hanke]]
 
:[[User:Ingo Hanke|Ingo Hanke]]
 
:Boris Hemkemeier
 
:Boris Hemkemeier

Revision as of 12:57, 26 November 2013

original photo from IqRS


Contents


For a more detailed description of everything see our main AppSec Research 2013 Web Site.


Presentations

Videos

Videos from the talks are available for Großer Saal and Aussichtsreich + Freiraum.

Slides

Quick links to the presentations. All slides are under CC-BY-SA license.

Thursday, August 22nd

Friday August, 23rd

Welcome

The German OWASP Chapter is hosting the global OWASP AppSec Research 2013 conference in Hamburg, Germany from August 20-23. Hamburg is the second biggest city in Germany, located in the north. To quote New York Times: No one tells you how pretty Hamburg is. We do.

The AppSec Research conference will be a premier gathering of Information Security leaders, also it has a research part.

Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 400-500 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology and many other verticals.

The conference will be held from August 20-23, 2013 at the Emporio Hamburg. It's centrally located in the heart of the city with a splendid view over Binnen-, Aussenalster and River Elbe.


Facts in a nutshell

Date
Trainings: August 20-21, 2013
Conference: August 22-23, 2013
Location
Emporio Hamburg
Program
Complete Program
Trainings
Open Source (Security) Showcase
HackPra Allstars Track
Events
Dinner ...
Sponsors
Sponsorship Description, find out more here.
Call for ...
Closed: May 15, was extended: May 22: Papers (Research).
Closed: Presentations (Industry). Talk teasers are here, Program comming soon.
Closed: Call for Trainings. Program is published
Closed: OWASP Open Source (Security) Showcase (OSS)
Registration
Is open, please see http://2013.appsec.eu/registration/ .
Mailinglist
please subscribe to: https://lists.owasp.org/mailman/listinfo/appseceu2013
Partners + Supporters
External Web Site

Sponsorship

AppSec Research is seeking for sponsors. We have several possibilities how you can promote your company, seek for employees and on the other side support the conference. Please find the description, pricing and possible items in a PDF here.

Thanks to our following sponsors

Platin
www.riverbed.com/products-solutions/products/application-delivery-stingray/

Gold Silver Bronze
    www.hpenterprisesecurity.com

www.imperva.com  www.f5.com  
www.barracuda.com   www.securenet.de  www.checkmarx.com  www.acunetix.com   www.denyall.com    www.securityinnovation.com   www.whitehatsec.com www.schutzwerk.com

www.tele-consulting.com   www.trustwave.com  www.ergon.ch  www.microsoft.com www.sap.com

Call for {Presentations,Papers,Trainings}

We had there separate "Calls":

Ticket Challenge

.. for the record

Teams

Conference Orga

Dirk Wetter (Chair)
Kai Jendrian (Co-Chair)
Ingo Hanke
Boris Hemkemeier
Achim Hoffmann
Martin Johns
Hartwig Gelhausen
Tobias Glemser
Sebastien Deleersnyder
Kelly Santalucia
Sarah Baso

Contact: orga2013//lists/appsec/eu


Twitter
Twitter: @appseceu
Twitter: @OWASP_de (German account)

<Germany>