Difference between revisions of "Denver"

From OWASP
Jump to: navigation, search
(Added May; nuked some SnowFROC links; archived April links and decks)
(Updated for June meeting; archived May notes.)
Line 3: Line 3:
 
== Local News ==
 
== Local News ==
  
===Next Chapter Meeting: [http://dowasp20120516.eventbrite.com/    RSVP Now!!! ] ===
+
===Next Chapter Meeting: June 20th at Hosting.com  [http://www.eventbrite.com/org/371792456   RSVP Now!!! ] ===
  
Chapter Meeting May 16th at 6'ish at Hosting.  [http://dowasp20120516.eventbrite.com/    RSVP HERE ] so we can order the right # of pizzas
+
Topic:
 
+
Emerging Threats - How Bad is It out There?
<!-- (Boulder's meeting will be on the 19th in case you can't attend Denver's). -->
+
  
''Please bring a laptop with WebScarab & Firefox installed''
+
* Emerging Threats - Real World Case Studies of What Cyber Criminals are Doing
 +
* Where is Mobile in the Mix?
 +
* Quantifying the Threats and Risks
 +
* Reporting - What Metrics are Leadership Teams Looking for Today?
  
===Hands-on XSS'ing===
 
 
Please bring a laptop that has wireless capability with a copy of WebScarab & Firefox installed.
 
Steve Kosten will discuss XSS and show and tell us how to use it.
 
The content will be geared towards those who have little to no experience using a web proxy or application testing  and want to learn, especially XSS.
 
 
WebScarab Download:
 
http://sourceforge.net/projects/owasp/files/WebScarab/20070504-1631/
 
  
Java Download:
+
Prior to his position as Directory of Strategy at SilverTail Systems, Laz served as head of Information Security with the Sears Online Business Unit. He has been involved in IT security for the past 20 years, consulting with and auditing Fortune 500 companies and government agencies. Laz holds several patents for controlling personally identifiable information, Information Security, and Information Technology. He is also an active contributor to security standards and policies initiatives regarding compliance and Information Security methodologies, policies, and web application security. Laz is a published author, has served in the United States Air Force, holds a Masters in Computer Information Security from the University of Denver and an MBA from Pepperdine University. He is also a fantastic speaker; you don't want to miss this one!
http://www.oracle.com/technetwork/java/javase/downloads/index.html
+
  
[http://dowasp20120516.eventbrite.com/    RSVP Now!!! ] so we can order the right # of pizzas
 
  
Future meetings are planned for: June, September, and October.
+
Chapter Meeting June 20th at 6'ish at Hosting.  [http://www.eventbrite.com/org/371792456    RSVP HERE ] so we can order the right # of pizzas
 +
 
 +
'''Thanks to Hosting for... hosting us, and thanks to SilverTail for providing dinner...'''
 +
 
 +
<!-- (Boulder's meeting will be on the 19th in case you can't attend Denver's). -->
 +
 
 +
 
 +
Future meetings are planned for: September and October.
  
 
==Chapter Board of Directors==
 
==Chapter Board of Directors==
Line 75: Line 74:
  
 
== Past Meetings ==
 
== Past Meetings ==
 +
[[Denver May 2012 meeting|Steve Kosten: XSS hands-on]]
 +
 
[[Denver April 2012 meeting|April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"]]
 
[[Denver April 2012 meeting|April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"]]
  

Revision as of 15:01, 19 June 2012

OWASP Denver

Welcome to the Denver chapter homepage. Chapter leader is Andy Lewis (many thanks to David Campbell for past leadership).
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is and open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.

Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

Local News

Next Chapter Meeting: June 20th at Hosting.com RSVP Now!!!

Topic: Emerging Threats - How Bad is It out There?

  • Emerging Threats - Real World Case Studies of What Cyber Criminals are Doing
  • Where is Mobile in the Mix?
  • Quantifying the Threats and Risks
  • Reporting - What Metrics are Leadership Teams Looking for Today?


Prior to his position as Directory of Strategy at SilverTail Systems, Laz served as head of Information Security with the Sears Online Business Unit. He has been involved in IT security for the past 20 years, consulting with and auditing Fortune 500 companies and government agencies. Laz holds several patents for controlling personally identifiable information, Information Security, and Information Technology. He is also an active contributor to security standards and policies initiatives regarding compliance and Information Security methodologies, policies, and web application security. Laz is a published author, has served in the United States Air Force, holds a Masters in Computer Information Security from the University of Denver and an MBA from Pepperdine University. He is also a fantastic speaker; you don't want to miss this one!


Chapter Meeting June 20th at 6'ish at Hosting. RSVP HERE so we can order the right # of pizzas

Thanks to Hosting for... hosting us, and thanks to SilverTail for providing dinner...


Future meetings are planned for: September and October.

Chapter Board of Directors

Here's the team that's putting it all together:

  • Chairman/Chapter Leader - Andy Lewis
  • Vice Chairman - Steve Kosten
  • Director of Communications - Craig Klosterman
  • Comm Vice-Director - Alan Darien
  • Outreach & Education Chair - James Synovec
  • Outreach & Education Vice Chair - Brad Carvalho
  • FROC Chair - Kathy Thaxton

NOTE: THIS WIKI IS USUALLY TERRIBLY OUT OF DATE. PLEASE FOLLOW @OWASP303 ON TWITTER AND/OR SUBSCRIBE TO THE MAILING LIST


OWASP Podcast

OWASP Podcast


funds to OWASP earmarked for Denver.


Questions, Comments

Questions can be directed to

  • Andy Lewis, Denver OWASP: alewis 'at' owasp.org


Chapter Meetings

Meetings are usually the 3rd Wednesday of the month. We are trying to have at least 2/quarter. If you can't make the Denver meeting, the Boulder meeting is usually the 3rd Thursday of the month.

Future Meetings

Meetings are planned for June, September, and October. We may do a social event or two also...


Past Meetings

Steve Kosten: XSS hands-on

April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"

February 15th 2012: Andy Lewis "Why OWASP? OWASP is the wheel. You don't need to reinvent it!

Denver January 2012 meeting January 18th, 2012| Greg Knaddison "How Does Drupal Security Stack up?"

September 14th 2011: Chris Schmidt "OWASP ESAPI"

March 17th 2011: Hands on "Hack a Thon"

September 22nd 2010: Eric Duprey: Application Vulnerability Shooting Gallery

August 18th 2010: Clint Pollock: Protecting Your Applications from Backdoors

June 2nd 2010: Front Range OWASP Conference

January 20th 2010: John Evans: Securing Webapps: An Illustrative Overview

November 18th 2009: Anton Rager: Advanced XSS

August 27th 2009: Jon Rose: Security in the Clouds

May 2009: Dr. Joseph McComb & and Daniel Weiske: Compliance and application security testing

March 2009: Front Range OWASP Conference (SnowFROC)

January 2009: David Campbell & Eric Duprey: Guided Tour: AppSec NYC '08 CTF

October 2008: Alex Smolen: The OWASP ASP .NET ESAPI

September 2008: John Dickson: Black Box vs. White Box: Different App Testing Strategies

August 2008: Dan Cornell: Static Analysis

July 2008: David Byrne & Eric Duprey: Grendel-Scan

June 2008: Front Range OWASP Conference: Jeremiah Grossman, Robert Hansen, and more!

May 2008: David Campbell & Eric Duprey: XSS Attacks & Defenses

April 2008: Ryan Barnett: Virtual Patching with ModSecurity

February 2008: Michael Sutton: SQL Injection Revisited

June 2007

April 2007

February 2007

January 2007

November 2006

Local Organizations of Interest

Mailing List

Join the OWASP Denver Mailing List to receive meeting notifications via email

Twitter Feed @owasp303

Denver OWASP has created a Twitter feed @owasp303 to keep you in the loop. Whilst the mailing list is primarily intended to be low-traffic and only provide updates regarding the times, locations, and topics for chapter meetings, the Twitter feed will also provide noteworthy appsec updates.

@OWASP303 Twitter Feed (follow us on Twitter!)



Resources

Denver OWASP Chapter Leaders
  • Andy Lewis, Denver OWASP: alewis 'at' owasp.org
Key OWASP Resources
Chapter Management Links

Denver OWASP Chapter SOPs

SnowFROC 2012 Schedule Draft