Difference between revisions of "BeNeLux OWASP Day 2013"
m (Fixed typo)
|Line 192:||Line 192:|
Revision as of 00:44, 18 October 2013
Welcome to OWASP BeNeLux 2013
Registration is now open!
Confirmed speakers Conference
- Dick Berlijn (ex Chief of Defence NL)
- Jan Joris Vereijken (ING)
- Tom Van Goethem (University Leuven)
- Jerome Nokin (Verizon Business)
- Nick Nikiforakis (University Leuven)
- Fakos Alexios and Jan Philipp (n.runs AG)
The OWASP BeNeLux Program Committee
- Bart De Win / Sebastien Deleersnyder/ Lieven Desmet/ David Mathy, OWASP Belgium
- Martin Knobloch / Ferdinand Vroom, OWASP Netherlands
- Jocelyn Aubert / Andre Adelsbach/ Thierry Zoller, OWASP Luxembourg
Event tag is #owaspbnl13
Donate to OWASP BeNeLux
OWASP BeNeLux training day and conference are free!
Registration is not now open:
To support the OWASP organisation, consider to become a member, it's only US$50!
Check out the Membership page to find out more.
Parking & roadmap:
There is a public parking close to the conference venue.
Roadmap and parking:
Conferenceday, November 29th
TBD (for details, check the Venue tab)
|09h00 - 10h00||Registration|
|10h00 - 10h15||OWASP Benelux Organization||Welcome|
|10h15 - 10h30||TBD||OWASP update|
|10h30 - 11h10||TBD|| Title |
|11h10 - 11h50||TBD|| Title |
|11h50 - 12h30||TBD|| Title |
|12h30 - 13h30||Lunch|
|13h30 - 14h10||TBD|| Title |
|14h10 - 14h50||TBD|| Title |
|14h50 - 15h30||TBD|| Title |
|15h30 - 15h50||Break|
|15h50 - 16h30||TBD|| Title |
|16h30 - 17h10||TBD|| Title |
|17h10 - 17h50||TBD||Panel Discussion about...|
|17h50 - 18h00||OWASP Benelux 2013 organization||Closing Notes|
Key note, by Jan Joris Vereijken (Chief Security Architect, ING)
Jan Joris Vereijken holds a Ph.D. in Computing Science from the Eindhoven Univerisity of Technology, where he worked on algebraic protocol verification. After a brief stint at Bell Laboratories to work on Software Engineering, he moved to ING, the Dutch banking conglomerate.
In his current role as Chief Security Architect, he is responsible for the security architecture in the 35-odd countries where ING has banking operations.
This presentation’s main goal is to provide decision makers, architects, administrators and developers with a comprehensive SharePoint security overview. We will introduce a SharePoint security model applicable to SharePoint versions 2010 and 2013. Then we will take a closer look at the use of different types of security principals and their effective use. This will be followed by covering security aspects when implementing and extending SharePoint to meet business needs and will be emphasized by showcasing common security pitfalls with examples throughout the presentation. This will be demonstrated with security down to the “nitty-gritty” details based on actual use cases and tips and pitfalls that have been encountered during security assessments and implementation of SharePoint solutions.
Jan Philipp (MCT since 1989, MCITP, MCSE) works as a security consultant at n.runs, where he is responsible for design and implementation security assessments of complex global SharePoint infrastructures and solutions for major German and international companies. He has been involved with SharePoint technologies from their inception with Digital Dashboards throughout their many development changes (TeamSpaces, MOSS etc.) to the present day SharePoint and SharePoint Live versions.
Alexios Fakos (CRISC, CSSLP) began his career in development as a Software Engineer back in 1999. After seven years of inspired insights in the software industry he joined n.runs to be part of the security team. Alexios is leading n.runs SDL services and he is since 2008 part of the German OWASP chapter. Alexios held presentations at OWASP AppSec US and Germany.
Remote Code Exection in WordPress: an analysis, by Tom Van Goethem (PhD Researcher, University of Leuven)
With over 13 million downloads, WordPress is one of the most popular open source blog platforms and content management systems. One of its key features is the installation of plugins. These are developed by third parties, but WordPress has to maintain its legacy codebase in order to remain compatible with these plugins. As this codebase makes use of unsafe functions, vulnerabilities may arise, affecting thousands websites - if not more. This presentation will focus on a vulnerability that has been present in WordPress versions up to September 2013. This vulnerability, which may lead to Remote Code Execution, was found by a simple combination of two publicly known elements: PHP Object Injection and unexpected behaviour of MySQL regarding Unicode characters.
Tom Van Goethem is passionate about web security. After getting a master's degree of Applied Informatics, he enrolled in a PhD at the University of Leuven. As a student with a chronic drinking problem, he still found some time to hunt bugs for fun (and profit).
Everything you always wanted to know about web-based device fingerprinting (but were afraid to ask), by Nick Nikiforakis (Postdoctoral Researcher, University of Leuven)
Billions of users browse the web on a daily basis, and there are single websites that have reached over one billion user accounts. In this environment, the ability to track users and their online habits can be very lucrative for advertising companies, yet very intrusive for the privacy of users.
In this talk, we are going to describe web-based device fingerprinting, i.e., the ability
will explain how device fingerprinting works, who is using, for what reason, and how people
are trying to defend against it today.
Nick Nikiforakis is a Postdoctoral Researcher at KU Leuven in Belgium. Nick's interests lie in the analysis of online ecosystems from a security and privacy perspective and he has published his work in top conferences of his field. More information about him can be found on his personal page: http://www.securitee.org .
Social Event, November 28th
Capture the Flag!
- Do you like puzzles?
- Do you like challenges?
- Are you a hacker?
Whether you are an experienced hacker or new enthusiast you should come to OWASP BeNeLux 2013 and participate in the Capture the Flag event November 29th 2013.
The OWASP CTF is especially designed to support challengers of all skill levels. The CTF contains multiple challenges in various fields related to application security. As every challenge gains you one point, you can pick and choose which challenge you want to play.
All you need is a laptop with a wifi card and your favorite (preferably) non-commercial tools.
So come, show off your skills, learn new tricks and above all have a good time at the CTF event.
Become a sponsor of OWASP BeNeLux
Donate to OWASP BeNeLux
Feel free to use the text below to promote our event!
We invite you to our next OWASP event: the BeNeLux OWASP Days 2013!
Free your agenda on the 28th and 29th of November, 2013.
The good news: free! No fee!
The bad news: there are only 280 seats available (first register, first serve)!