Difference between revisions of "Denver"

From OWASP
Jump to: navigation, search
(January 2013 meeting)
(3 intermediate revisions by one user not shown)
Line 2: Line 2:
  
 
== Local News ==
 
== Local News ==
 +
===THANK YOU TO OUR SPONSORS===
 +
[[File:DenverCateringSponsor2013SouthSeas.jpg]]
  
===Next Chapter Meeting: October 17th at Hosting.com  [http://dowasp201210.eventbrite.com/   RSVP Now!!! ] ===
+
A big thank you to [http://www.southseascorp.com/ South Seas Corporation] for sponsoring all catering for our 2013 monthly chapter meetings!! It is much appreciated!
  
Pizza and Chapter Business starting at 6, presentation starting at about 6:30...
+
===Next Chapter Meeting: January 16th at Hosting.com  [http://201301denverowasp.eventbrite.com/#    RSVP Now!!! ] ===
  
[http://dowasp201210.eventbrite.com/ RSVP here]
+
Food and Chapter Business starting at 6, presentation starting at about 6:30.
  
'''Topic: DevOps: The Answer App Security didn't know we needed'''
+
[http://201301denverowasp.eventbrite.com/# RSVP]
  
Is security still an afterthought in your SDLC?  Is "the" security practitioner in your SDLC a pariah?  Are you ready for that to change?  Raf will share some insight that might help YOU and YOUR team FINALLY integrate security into your SDLC...
+
'''Topic: Reducing Risk in your software applications'''
  
'''About Raf:''' Rafal Los, Chief Security Evangelist for Hewlett-Packard Software, combines nearly 15 years of subject-matter expertise in information security with a critical business risk management perspectiveFrom technical research to building and implementing enterprise application security programs, Rafal has a track record with organizations of diverse sizes and verticalsHe is a featured speaker at events around the globe, and has presented at events produced by OWASP, ISSA, Black Hat,  and SANS among many others. He stays active in the community by writing, speaking and contributing research, representing HP in OWASP, the Cloud Security Alliance and other industry groups. His blog, Following the White Rabbit, with his unique perspective on security and risk management has amassed a following from his industry peers, business professionals, and even the media and can be found at
+
Find out what works to reduce risk in applicationsIt's not just about your internal developers writing secure code or pen testers hacking away at your appsI will share some statistics    and trends around the state of software security and the best ways to address the threat. What are the most mature organizations doing in application security?  The tips, techniques, and strategies presented here are gleaned from the experience of Veracode scanning over 130 billion lines of code and working with some of the world's largest companies.
  
http://hp.com/go/white-rabbit.
+
'''About Dave Ferguson:''' Dave Ferguson is a Solutions Architect with Veracode and is based in Dallas, TX. In the past he was a Principal Consultant on the application security consulting team at FishNet Security and an application developerHe has been an OWASP member and contributor since 2006 and is a former leader of the Kansas City OWASP chapter. Dave is author of the Forgot Password Cheat Sheet and was interviewed for podcast #83. He writes a blog at http://appsecnotes.blogspot.com and holds CISSP and CSSLP certifications
 
+
Prior to joining HP, Los defined what became the software security program and served as a regional security lead at a Global Fortune 100 contributing to the global organization’s security and risk-management strategy internally and externallyRafal prides himself on being able to add a ‘tint of corporate realism’ to information security.
+
 
+
Rafal received his B. S. in Computer Information Systems from Concordia University, River Forest, Ill.
+
 
+
* Twitter:@Wh1t3Rabbit
+
* Speaker URL:hp.com/go/white-rabbit
+
* Facebook:facebook.com/Wh1t3RabbitPage
+
  
 
'''About the chapter:'''
 
'''About the chapter:'''
 
Chapter Meetings are held the 3rd Wednesday of designated months for the Denver Chapter, and the 3rd Thursday of designated months for the [[Boulder|Boulder]] Chapter.  If you have an idea for a topic or speaker or would like to present, please
 
Chapter Meetings are held the 3rd Wednesday of designated months for the Denver Chapter, and the 3rd Thursday of designated months for the [[Boulder|Boulder]] Chapter.  If you have an idea for a topic or speaker or would like to present, please
reach out to Andy Lewis, Denver OWASP Chapter Leader: alewis 'at' owasp.org
+
reach out to Steve Kosten, Denver OWASP Chapter Leader: steve 'dot' kosten 'at' owasp.org
  
 
<!-- June 20th at 6'ish at Hosting.  [http://www.eventbrite.com/org/371792456    RSVP HERE ] so we can order the right # of pizzas -->
 
<!-- June 20th at 6'ish at Hosting.  [http://www.eventbrite.com/org/371792456    RSVP HERE ] so we can order the right # of pizzas -->
  
'''Thanks to [http://www.hosting.com/ Hosting.com] for... hosting us, and thanks to [http://www.hpenterprisesecurity.com HP] for providing a speaker and dinner for October's meeting...'''
+
'''Thanks to [http://www.hosting.com/ Hosting.com] for hosting us, [http://www.southseascorp.com/ South Seas Corporation] for providing food for our meetings and thanks to [http://veracode.com Veracode] for providing a speaker for this meeting...'''
  
  
Line 43: Line 37:
 
* Outreach & Education Chair - James Synovec
 
* Outreach & Education Chair - James Synovec
 
* Outreach & Education Vice Chair - Brad Carvalho
 
* Outreach & Education Vice Chair - Brad Carvalho
* FROC Chair - Kathy Thaxton
+
* FROC Chair - Micah Tapman
 +
* FROC Chair Emeritus - Kathy Thaxton
  
NOTE: THIS WIKI IS OCCASIONALLY TERRIBLY OUT OF DATE.  PLEASE FOLLOW @OWASP303 ON TWITTER AND/OR [http://lists.owasp.org/mailman/listinfo/owasp-denver SUBSCRIBE TO THE MAILING LIST] AND/OR join the OWASP Denver Linked In group.
+
NOTE: PLEASE CONSIDER FOLLOWING US AT @OWASP303 ON TWITTER AND/OR [http://lists.owasp.org/mailman/listinfo/owasp-denver SUBSCRIBE TO THE MAILING LIST] AND/OR join the OWASP Denver Linked In group.
  
 
<!-- =====Missed the con?=====
 
<!-- =====Missed the con?=====
Line 67: Line 62:
 
Questions can be directed to  
 
Questions can be directed to  
  
*Steve Kosten, Denver OWASP: skosten 'at' owasp.org
+
*Steve Kosten, Denver OWASP: steve 'dot' kosten 'at' owasp.org
  
 
<hr>
 
<hr>
Line 164: Line 159:
  
 
=====Denver OWASP Chapter Leaders=====
 
=====Denver OWASP Chapter Leaders=====
*Andy Lewis, Denver OWASP: alewis 'at' owasp.org
+
*Steve Kosten, Denver OWASP: steve.kosten 'at' owasp.org
  
 
=====Key OWASP Resources=====
 
=====Key OWASP Resources=====

Revision as of 00:28, 3 January 2013

OWASP Denver

Welcome to the Denver chapter homepage. Chapter leader is Steve Kosten.
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is and open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.

Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

Local News

THANK YOU TO OUR SPONSORS

DenverCateringSponsor2013SouthSeas.jpg

A big thank you to South Seas Corporation for sponsoring all catering for our 2013 monthly chapter meetings!! It is much appreciated!

Next Chapter Meeting: January 16th at Hosting.com RSVP Now!!!

Food and Chapter Business starting at 6, presentation starting at about 6:30.

RSVP

Topic: Reducing Risk in your software applications

Find out what works to reduce risk in applications. It's not just about your internal developers writing secure code or pen testers hacking away at your apps. I will share some statistics and trends around the state of software security and the best ways to address the threat. What are the most mature organizations doing in application security? The tips, techniques, and strategies presented here are gleaned from the experience of Veracode scanning over 130 billion lines of code and working with some of the world's largest companies.

About Dave Ferguson: Dave Ferguson is a Solutions Architect with Veracode and is based in Dallas, TX. In the past he was a Principal Consultant on the application security consulting team at FishNet Security and an application developer. He has been an OWASP member and contributor since 2006 and is a former leader of the Kansas City OWASP chapter. Dave is author of the Forgot Password Cheat Sheet and was interviewed for podcast #83. He writes a blog at http://appsecnotes.blogspot.com and holds CISSP and CSSLP certifications

About the chapter: Chapter Meetings are held the 3rd Wednesday of designated months for the Denver Chapter, and the 3rd Thursday of designated months for the Boulder Chapter. If you have an idea for a topic or speaker or would like to present, please reach out to Steve Kosten, Denver OWASP Chapter Leader: steve 'dot' kosten 'at' owasp.org


Thanks to Hosting.com for hosting us, South Seas Corporation for providing food for our meetings and thanks to Veracode for providing a speaker for this meeting...


Future meetings are planned for: stay tuned for 2013.

Chapter Board of Directors

Here's the team that's putting it all together:

  • Chairman/Chapter Leader - Steve Kosten
  • Director of Communications - Craig Klosterman
  • Comm Vice-Director - Alan Darien
  • Outreach & Education Chair - James Synovec
  • Outreach & Education Vice Chair - Brad Carvalho
  • FROC Chair - Micah Tapman
  • FROC Chair Emeritus - Kathy Thaxton

NOTE: PLEASE CONSIDER FOLLOWING US AT @OWASP303 ON TWITTER AND/OR SUBSCRIBE TO THE MAILING LIST AND/OR join the OWASP Denver Linked In group.


OWASP Podcast

OWASP Podcast


funds to OWASP earmarked for Denver.


Questions, Comments

Questions can be directed to

  • Steve Kosten, Denver OWASP: steve 'dot' kosten 'at' owasp.org


Chapter Meetings

Meetings are usually the 3rd Wednesday of the month. We are trying to have at least 2/quarter. If you can't make the Denver meeting, the Boulder meeting is usually the 3rd Thursday of the month.

Future Meetings

Meetings are planned for the 3rd Wednesdays of September and October. We may do a social event or two also...


Past Meetings

Laz: Emerging Threats

Steve Kosten: XSS hands-on

April 18th 2012: Tim Van Cleave "Intro to WebScarab and WebGoat"

February 15th 2012: Andy Lewis "Why OWASP? OWASP is the wheel. You don't need to reinvent it!

Denver January 2012 meeting January 18th, 2012| Greg Knaddison "How Does Drupal Security Stack up?"

September 14th 2011: Chris Schmidt "OWASP ESAPI"

March 17th 2011: Hands on "Hack a Thon"

September 22nd 2010: Eric Duprey: Application Vulnerability Shooting Gallery

August 18th 2010: Clint Pollock: Protecting Your Applications from Backdoors

June 2nd 2010: Front Range OWASP Conference

January 20th 2010: John Evans: Securing Webapps: An Illustrative Overview

November 18th 2009: Anton Rager: Advanced XSS

August 27th 2009: Jon Rose: Security in the Clouds

May 2009: Dr. Joseph McComb & and Daniel Weiske: Compliance and application security testing

March 2009: Front Range OWASP Conference (SnowFROC)

January 2009: David Campbell & Eric Duprey: Guided Tour: AppSec NYC '08 CTF

October 2008: Alex Smolen: The OWASP ASP .NET ESAPI

September 2008: John Dickson: Black Box vs. White Box: Different App Testing Strategies

August 2008: Dan Cornell: Static Analysis

July 2008: David Byrne & Eric Duprey: Grendel-Scan

June 2008: Front Range OWASP Conference: Jeremiah Grossman, Robert Hansen, and more!

May 2008: David Campbell & Eric Duprey: XSS Attacks & Defenses

April 2008: Ryan Barnett: Virtual Patching with ModSecurity

February 2008: Michael Sutton: SQL Injection Revisited

June 2007

April 2007

February 2007

January 2007

November 2006

Local Organizations of Interest

Mailing List

Join the OWASP Denver Mailing List to receive meeting notifications via email

Twitter Feed @owasp303

Denver OWASP has created a Twitter feed @owasp303 to keep you in the loop. Whilst the mailing list is primarily intended to be low-traffic and only provide updates regarding the times, locations, and topics for chapter meetings, the Twitter feed will also provide noteworthy appsec updates.

@OWASP303 Twitter Feed (follow us on Twitter!)



Resources

Denver OWASP Chapter Leaders
  • Steve Kosten, Denver OWASP: steve.kosten 'at' owasp.org
Key OWASP Resources
Chapter Management Links

Denver OWASP Chapter SOPs

SnowFROC 2012 Schedule Draft