Difference between revisions of "Boulder"

From OWASP
Jump to: navigation, search
(December - Date TBA “Capture the Holiday flag”)
(31 intermediate revisions by 6 users not shown)
Line 1: Line 1:
{{Chapter Template|chaptername=Boulder|extra=The chapter leaders are [mailto:kthaxton@businesspartnersolutions.com Kathy Thaxton], [mailto:mrhits777@gmail.com Jeremy Martinez], and [mailto:Andrew.Riesel@GMail.com Andrew Riesel]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}
+
{{Chapter Template|chaptername=Boulder|extra=The chapter leader is [[User:Mark_Major|Mark Major]].
 +
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-boulder|emailarchives=http://lists.owasp.org/pipermail/owasp-boulder}}
  
<paypal>Boulder</paypal>
+
== Upcoming Events ==
 +
====Thursday, February 21st at 6pm – Analysis of Drupal Security====
  
Next Meeting of the Boulder OWASP will be September 24, 2009 at Staples in Broomfield.
+
'''When''': Thursday, February 21st at 6:00pm
 +
<br>'''Where''': [https://aerstone.com/ Aerstone], located at [https://maps.google.com/maps?q=1711+Pearl+St,+Boulder,+CO+80302&hl=en&ll=40.018955,-105.272412&spn=0.005801,0.016512&sll=40.019446,-105.273058&layer=c&cbp=13,345.63,,0,0.03&cbll=40.019323,-105.273016&hnear=1711+Pearl+St,+Boulder,+Colorado+80302&t=m&z=17&panoid=5v0RhKi7sjpi-Z5HcgKFFw 1711 Pearl St.] (3rd floor).
 +
<br>'''Parking''': Free through the [http://files.meetup.com/3503072/Parking.png Whittier Neighborhood Zone].
 +
<br>'''RSVP''': available through [http://www.meetup.com/OWASP-Boulder/events/102677222/ MeetUp.com]
 +
<br>'''Virtual meeting options''': see  [http://www.meetup.com/OWASP-Boulder/events/102679412/ MeetUp.com] .
  
 +
'''Agenda'''
 +
<br>6:00 - 6:30 Food, drink, and networking
 +
<br>6:30 - 7:15 Chapter business and group discussion
 +
<br>7:15 - 8:00 Featured presentation
 +
 +
'''Featured Presentation: Analysis of Drupal Security'''
 +
<br>An overview of how Drupal, one of the most commonly used, open source content management systems, is secured against the OWASP Top Ten, some common configuration mistakes, and emerging trends on Drupal exploits.  What attacks are targeting Drupal applications?  Personal thoughts from a developer, user and admin of Drupal sites about clear steps that can be taken to improve security with Drupal applications.
 +
 +
'''Speaker Bio'''
 +
<br>Andrew has been a developer for 7 years.  He began as a PHP and C# developer, where he entered web application development by designing and creating web services.  For the last 5 years he has been a web developer in Boulder.  He has always had an interest in web application, network, and cyber security and has brought those interests into his web developer role with securing web applications.  He is often amused how passwords are still stored as plain text, untrusted HTML input is not validated, and GET parameters are not sanitized.
 +
 +
Seating is limited and is prioritized for those who RSVP. Parking is available through the Whittier Neighborhood Zone. Food and drinks will be provided and there will be a networking session preceding the meeting. As always, meetings are free to attend.
  
NEXT MEETING SEPTEMBER 24TH. SEE AGENDA BELOW
+
====Special Thanks====
 +
The Boulder chapter is grateful for the continued sponsorship of Aerstone. Thank you for providing the venue, refreshments, and other resources necessary to keep the chapter running strong.
  
=== Directions to Staples: ===
+
[[File:BoulderSponsorAerstone.png]]
  
'''Staples:  [http://maps.google.com/maps?q=1+Environmental+Way,+Broomfield,+CO+80021,+USA&sa=X&oi=map&ct=title One Environmental Way, Broomfield, Co. 80021]'''
+
====Wednesday, Wednesday, February 20th at 6pm – CTF Project Development====
  
=== Agenda ===
+
Plan, plot, hack, hang out.
* 6 to 7:00 Dinner @ [http://maps.google.com/maps?f=q&hl=en&geocode=&q=Corporate+Express+1+Environmental+Way,+Broomfield+colorado&sll=39.935803,-105.13092&sspn=0.077395,0.144711&ie=UTF8&ll=39.926934,-105.126565&spn=0.009676,0.018089&z=16&iwloc=A Staples CE - Broomfield]
+
  
* 7pm to 8:30 pm Cross-site scripting lab
+
'''When''': Wednesday, February 20th at 6:00pm
Sponsor: '''Nope, no sponsor. It'a your chapter, BYO dinner and/or order pizza at 6'ish'''
+
<br>'''Where''': [https://aerstone.com/ Aerstone], located at [https://maps.google.com/maps?q=1711+Pearl+St,+Boulder,+CO+80302&hl=en&ll=40.018955,-105.272412&spn=0.005801,0.016512&sll=40.019446,-105.273058&layer=c&cbp=13,345.63,,0,0.03&cbll=40.019323,-105.273016&hnear=1711+Pearl+St,+Boulder,+Colorado+80302&t=m&z=17&panoid=5v0RhKi7sjpi-Z5HcgKFFw 1711 Pearl St.] (3rd floor).
 +
<br>'''Parking''': Free through the [http://files.meetup.com/3503072/Parking.png Whittier Neighborhood Zone].
 +
<br>'''RSVP''': available through [http://www.meetup.com/OWASP-Boulder/ MeetUp.com]
 +
<br>'''Virtual meeting''': available through [https://questconsultants.webex.com/ WebEx].
 +
<br>(Please call me if the door is locked or WebEx is down.)
  
Speaker: tbd
+
The standing agenda includes status updates on:
 +
* Participant VM
 +
* Scoreboard
 +
* Challenge management
 +
* Challenge development
 +
* Challenge-framework integration
 +
* General project administration
 +
* Roadblocks
  
=== Logistics ===
+
Any time left over will be used for collaboration and coding.
Please bring a wifi equipped laptop.  We recommend the [http://www.owasp.org/index.php/Category:OWASP_Live_CD_2008_Project OWASP LiveCD].  Go ahead and download it and familiarize yourself with it ahead of time, if you're so inclined.
+
  
 
+
[[Category:OWASP Chapter]]
Following the meeting we will have informal discussions over beverages at the [http://maps.google.com/maps?f=q&hl=en&geocode=&q=Gordon+Biersch+Brewery+Broomfield+colorado&ie=UTF8&ll=39.935803,-105.13092&spn=0.077395,0.144711&z=13&iwloc=A Gordon Biersch Brewery and Restaurant].
+
[[Category:Colorado]]
 
+
 
+
-----------------------------------------------------------------------
+
 
+
== October and November 2009 Meetings will be joint with the Denver OWASP at a downtown location TBA ==
+
===Unfortunately we are going to have to cancel this months (September 2009) meeting.  Our sponsor presenter was unable to make it out here at the last minute due to some budgeting constraints.
+
 
+
David Campbell (Denver OWASP) and I will be holding joint meetings for October and November at a downtown location in order to make it convenient for all of our members.  We will be focusing on Cloud Security for the rest of the year as this has become a hot topic and pertinent to 2010 planning for many.===
+
 
+
 
+
== December  - Date TBA  “Capture the Holiday flag” ==
+
 
+
We are planning on reserving space at a restaurant.  What better way to Capture the Flag than over a couple of beers?
+

Revision as of 23:41, 19 February 2013

Contents

OWASP Boulder

Welcome to the Boulder chapter homepage. The chapter leader is Mark Major.
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is and open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.

Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

Upcoming Events

Thursday, February 21st at 6pm – Analysis of Drupal Security

When: Thursday, February 21st at 6:00pm
Where: Aerstone, located at 1711 Pearl St. (3rd floor).
Parking: Free through the Whittier Neighborhood Zone.
RSVP: available through MeetUp.com
Virtual meeting options: see MeetUp.com .

Agenda
6:00 - 6:30 Food, drink, and networking
6:30 - 7:15 Chapter business and group discussion
7:15 - 8:00 Featured presentation

Featured Presentation: Analysis of Drupal Security
An overview of how Drupal, one of the most commonly used, open source content management systems, is secured against the OWASP Top Ten, some common configuration mistakes, and emerging trends on Drupal exploits. What attacks are targeting Drupal applications? Personal thoughts from a developer, user and admin of Drupal sites about clear steps that can be taken to improve security with Drupal applications.

Speaker Bio
Andrew has been a developer for 7 years. He began as a PHP and C# developer, where he entered web application development by designing and creating web services. For the last 5 years he has been a web developer in Boulder. He has always had an interest in web application, network, and cyber security and has brought those interests into his web developer role with securing web applications. He is often amused how passwords are still stored as plain text, untrusted HTML input is not validated, and GET parameters are not sanitized.

Seating is limited and is prioritized for those who RSVP. Parking is available through the Whittier Neighborhood Zone. Food and drinks will be provided and there will be a networking session preceding the meeting. As always, meetings are free to attend.

Special Thanks

The Boulder chapter is grateful for the continued sponsorship of Aerstone. Thank you for providing the venue, refreshments, and other resources necessary to keep the chapter running strong.

BoulderSponsorAerstone.png

Wednesday, Wednesday, February 20th at 6pm – CTF Project Development

Plan, plot, hack, hang out.

When: Wednesday, February 20th at 6:00pm
Where: Aerstone, located at 1711 Pearl St. (3rd floor).
Parking: Free through the Whittier Neighborhood Zone.
RSVP: available through MeetUp.com
Virtual meeting: available through WebEx.
(Please call me if the door is locked or WebEx is down.)

The standing agenda includes status updates on:

  • Participant VM
  • Scoreboard
  • Challenge management
  • Challenge development
  • Challenge-framework integration
  • General project administration
  • Roadblocks

Any time left over will be used for collaboration and coding.