Hyderabad

From OWASP
Jump to: navigation, search

Welcome to the OWASP Hyderabad chapter homepage.

OWASP - Hyderabad Chapter Board Members

Scope of the board is to discuss and approve local activities, meetings and plans.The board meetings will be announced at a later date.

The board currently includes the following members :

Core Team Members - 2017
Shalem Raj - Cognizant Technology Solutions : Chapter Leader
Rajesh Gopal - Fortune 500 Organisation
Bhaskar Puppala - Fortune 500 Organisation
Achanta Sathya Phani Bapi Raju - CSC
Saikrishna Gobburi - Pramati Technologies Pvt Ltd

Information about future meets can be seen in the Upcoming Meetings section below.

Location Details

Hyderabad is the capital of southern India's Telangana state. A major center for the technology industry, it's home to many upscale restaurants and shops. Its historic sites include Golconda Fort, a former diamond-trading center that was once the Qutb Shahi dynastic capital. The Charminar, a 16th-century mosque whose 4 arches support towering minarets, is an old city landmark near the long-standing Laad Bazaar.

Panorama of Hyderabad, as seen from the Hussain Sagar lake. Source: https://en.wikipedia.org/wiki/Hyderabad#/media/File:Hydskyline.jpg

More details about Hyderabad location available @https://en.wikipedia.org/wiki/Hyderabad

OWASP Hyderabad

Welcome to the Hyderabad chapter homepage. {{{extra}}}
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.


Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

Participants

OWASP Local Chapter meetings are free and open. Our chapter's meetings are informal and encourage open discussion of all aspects of application security. Anyone in our area interested in web application security is welcome to attend. We encourage attendees to give short presentations about specific topics.


Stay Updated

Click here to join the local chapter mailing list

Follow OWASP Hyderabad on your favorite social media sites:

Twitter mini.png Facebook mini.png

Share OWASP Hyderabad on your favorite social media sites:

Presentations are invited from speakers, Please contacts us at our Telegram Group @https://goo.gl/EHqdLM

(Don't share personal details like contact numbers here, because its an open group, your privacy is our concern)

Presenters are encouraged to use OWASP presentation template for slides preparation.

Follow us at our Telegram, Twitter and Facebook handles to get latest information !

Upcoming Meetings & Events

Stay tuned for 2018 updates - Exciting activities are under plan !

Meeting Details:

June - 2018

Venue: coMakeIT Software Pvt Ltd

Address: 7th Floor, Block-I, My Home Hub, Hitech City, Madhapur, Hyderabad, INDIA

Event Start Time: Saturday, 23rd June, 2018 at 10:00 AM (IST)

Event Registration URL: https://tinyurl.com/yc9cb6hg

Agenda:

1) Adapting to DevSecOps in Agile World

In this talk, speaker will try talk about basics of DevSecOps and its benefits when we integrate it in Agile SDLC space.

2) Understanding the internals of 'Server-Side Request Forgery' (SSRF)

Here speaker will try to touch the basics about how application communicates with end devices and using the same he will try to explain SSRF issue and criticality of it, if exploited.

About Speakers:

1) Saikrishna Gobburi has around 8.5 years of work experience on QA automation, performance and security testing .Currently he is working as Principle engineer with Pramati technologies. He is also associated as core member with OWASP-Hyderabad. For more details please visit: https://www.linkedin.com/in/saikrishna-gobburi-b0088118/

2) Bhaskar Puppala is an Information Security Professional, working as a consultant for a fortune 500 company and has 8.5 years of experience. He is more interested in application security area and love to share his knowledge when possible. He also has some experience in bug bounty programs and listed on couple of Security Hall of Fames. For more details please visit : https://in.linkedin.com/in/bhaskar-puppala-3bb11316

Our Facebook URL: https://www.facebook.com/OWASPHyderabad/

Our Twitter URL: https://twitter.com/owasphyderabad

Our Telegram URL: https://goo.gl/EHqdLM

Mar - 2018

Venue: Daspalla Hotel

Address: Rd Number 37, CBI Colony, Jubilee Hills, Hyderabad, Telangana 500033, Phone: 040 6654 5678

Event Start Time: Saturday, 10th Mar, 2018 at 10:00 AM (IST)

Agenda:

1) Does your Pentesting cover all the basis of IT Security ?

This talk focuses on how to align the security validation of a web application with the three basic elements of security namely,Confidentiality,Integrity, and Availability (CIA). The test effectiveness can be achieved by analyzing the requirements of each element and identifying the potential breaches that can compromise each element. The efficiency should be built by relating these breaches with the known OWASP Top 10 and other vulnerabilities and, leveraging that knowledge to identify the testing approach - static and dynamic throughout the SDLC.

About Speakers:

Bhushan Gupta has over 30 years of experience in software engineering, 23 of which have been in the software industry. Although recognized for his contributions in the areas of software engineering such as agile processes and quality methods and metrics, Bhushan has taken a vigorous interest in web application security and is keen on applying pragmatic software development practices that yield a secure product. He is one of the leaders of the OWASP Portland Chapter. Bhushan has been a speaker, a panelist, and a reviewer for software quality and security organizations. As a change agent, Bhushan volunteers his time and energy for organizations that promote software security and quality. He has a MS degree in Computer Science from New Mexico Institute of Mining and Technology, Socorro, New Mexico, 1985.

Facebook URL: https://www.facebook.com/OWASPHyderabad/

Twitter URL: https://twitter.com/owasphyderabad

Telegram URL: https://goo.gl/EHqdLM

Registration URL: https://goo.gl/tEXnec

Feb-2018

Venue: coMakeIT

7th Floor, Block-I, My Home Hub, Hitech City, Madhapur, Hyderabad, INDIA

Time: Saturday, 03rd Feb, 2018 at 10:30 AM (IST)

Agenda:

1) Mobile Application Pentest & Mobile Application Ransomware

2) Using Static Analyser tools while coding

About Speakers:

1) Spv Reddy is an Application Security Analyst at IMImobile Pvt Ltd, member of National Technical Committee Member at National Cyber Safety and Security Standards

Also a Steering Committee Lead Member in National Information Security Summit.

2) Dathu Rachapudi is having 9 years of experience with 6+ years into Application Security only. He is currently working with ValueLabs as a “Technical Lead-Security”

He likes to teach and a happy a bug hunter during his leisure time.

Dec-2017

WhatsApp Image 2017-12-15 at 11.09.39 PM.jpg

Time & Venue:

@15/Dec/2017

KFC location, Shilparamam, Hi-Tech city, Hyderabad

Agenda:

1. Planning for Jan 20th 2018 general OWASP meet - Done

2. Need to clear OWASP mail account - Done

Attendees : Hyderabad OWASP Core Team

Sec-2017

WhatsApp Image 2017-12-15 at 10.13.27 PM.jpg

Time & Venue:

@03/Sep/2017

Cafe Coffee day, Road Number 10, Banjara Hills, Hyderabad

Below decisions were made after careful discussions

1. Uploading of OWASP presentation template, speakers should make use of this template to prepare their presentation

2. Recording the technical demo is mandate for presenters

Attendees : Hyderabad OWASP Core Team

July 2017

Time & Venue:

OpenText Technologies, Building No-14, 3rd Floor, Raheja  Mindspace, HITEH City, Hyderabad

Saturday, July 15th, 2017 at 10:30 AM (IST)

Agenda:

1. Introduction to DevOps and its Tools - Krishna Reddy Pedala

2. API Security Auditing using RESTED Plug-in - Vikas Kumar Pal

About the speaker:

Krishna Reddy Pedala is currently working as an Sr.Information Security consultant in financial sector. His previous endeavour was with Microsoft and has 9+ years of experience in Information security domain  with expertise in service industry and banking domains.

Vikas Kumar Pal is an information security professional working with Ceredox Technologies Pvt Ltd, Hyderabad with an interest in research and development in the areas of Application Security, Penetration Testing and Web Application Development.

Feb 2017

Time & Venue:

Starbucks, Opp: Cybergateway, HiTech City, Hyderbad

Monday, February 20th, 2017 at 7.30 PM (IST)

Agenda:

Topic: New Core Team Meeting

Road map for year 2017

Changes in core team members responsibilities

Getting OWASP accounts for core members

Administration of all social accounts of OWASP Hyderabad Chapter

April 2016

Time & Venue:

OpenText Technologies, Building No-14, 3rd Floor, Raheja  Mindspace, HITEH City, Hyderabad

Saturday, April 2nd, 2016 at 10:30 AM (IST)

Agenda:

Topic: Mobile application security and testing by Satish Kumar Patnaik

About the speaker - Satish Kumar Patnayak : he is currently working as an Senior Information Security Consultant financial sector and has 5+ years of experience in Information Security domain with different domain expertise in service industry and banking domains. His areas of interest are android security, ios security.

February 2016

Time & Venue:

Saturday, February 27th, 2016 at 10:30 AM (IST)

Location: Pramati Technologies Private Limited, Mid Town 6-3-348 Road No. 1, Banjara Hills, Hyderabad, Telangana, India

Agenda:

Microsoft Threat Modeling Tool 2016 by Krishna Reddy Padala

Creating DFD STRIDE Model Identifying STRIDE Threats by DFD, Mitigation Techniques and Technologies

About the speaker: Krishna Reddy Padala, he is currently working as an Senior Information Security Consultant financial sectore and worked with Microsoft and has 8+ years of experience in Information Security domain with different domain expertise in service industry and banking domains. QUALYS GUARD Certified Vulnerability Management Specialist.Certified Ethical Hacker from EC Council.Worked extensively on Web Application Security, Secure Code Reviews in Banking & Financial, Healthcare, Retail, Logistics domains.

Previous Meets:

May 11, 2013

Venue:

CA Technologies, 115, IT Park Area, Nanakramguda,
Gachibowli - (Phone - 040 6687 8000), Hyderabad


Agenda:
Exploiting Java 0-day by Ravindra and Raghuveer, CA Technologies
Compliance and Governance by Shalem Raj, Cognizant.

February 9, 2013

Date & Time: Saturday, February 9, 2013 from 10:00 AM to 1:00 PM

Venue: CA Technologies
115, IT Park Area
Nanakramguda,
Gachibowli - (Phone - 040 6687 8000)
Hyderabad


Agenda: IBM Appscan - An automated approach to web app security by Rohit Tamma
Insecure Storage in iPhone applications by Satish Bommisetty


Speakers:

Rohit Tamma Rohit Tamma has been working in the field of Application Security since 3.5 years. He has experience in Vulnerability Assessments and Penetration Testing of web applications. He is passionate about Mobile security with special interest in Android security. He is currently working with ADP.

Satish Bommisetty Satish is an Information Security Professional with 6.5 years of experience in penetration testing of web applications and mobile applications. He is currently working with ADP as a security analyst. He is a Facebook whitehat. He also reported vulnerabilities in Bing, Linkedin and Paypal.


October 27, 2012

Date & Time: Saturday, October 27, 2012 at 11:00 AM (IST) .

Venue:

Invesco private Limited
15th Floor , North Block, Beside Raidurg Police Station
DivyaSree Orion SEZ
Hyderabad, Andhra Pradesh 500032


Agenda:

A bird'd eye view of securing Web Applications by Imran Mohammed

SSDLC BSIMM by M S Sripathi


Speakers

Imran Mohammed

Mohammed Imran works as Researcher at TCS, Innovation Labs. He also leads the Null Hyderabad chapter and is the Board member of OWASP Hyderabad Chapter. Imran is a CEH and his interests include application security assessment, penetration testing and secure code review. When not at work he practices horse riding and marksmanship.

Sreepati M S

Sripati (http://www.sripati.info/) has little study, moderate & varied experience (dev-2 yrs., security-4+ yrs.), and lots of aspirations (as far as security goes, at least). He started his career in web-application development, then took a detour towards quality compliance for some time (~6 months) and later moved to security compliance. Still learning the ropes, he believes there is so much to learn and so little time! Interested in web-app security (as if ISMS implementation is not enough), so that says something about his guts! He thinks OWASP is a very good platform for web-app people, and that since he joined OWASP, he has learnt a lot from people around him .


Sponsor

Invesco Pvt Ltd


August 11, 2012

Date & Time: Saturday, Aug 11, 2012 at 10:30 AM .

Venue:

ADP pvt ltd
Kothaguda
Ground floor, Block C Laxmi cyber city Opposite TCS e-park
Hyderabad, Andhra Pradesh 500081

Agenda:

HTML5 Security Part II by Krishna Chaitanya

Speakers

Krishna Chaitanya T

Krishna Chaitanya T is a web geek working at Security & Privacy Research Lab, Infosys Labs. He is very much passionate about the web with special interest on Web security and areas such as HTML5, JavaScript, Web browsers, social networking platforms etc. He is a regular blogger and speaker at technical events. For his contributions to technical communities, he has been awarded Microsoft MVP award for 3 consecutive years-ASP.NET MVP(2010) and Internet Explorer MVP (2011, 2012). He is also pursuing M.S by Research at IIIT-Hyd with focus on security aspects of the modern web. When not at work he practices Yoga and plays Chess.

Sponsor

Adp.jpg


May 19, 2012

Date & Time: Saturday, May 19, 2012 at 10:30 AM .

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Agenda:

HTML5 Security by Krishna Chaitanya

Speakers

Krishna Chaitanya T

Krishna Chaitanya T is a web geek working at Security & Privacy Research Lab, Infosys Labs. He is very much passionate about the web with special interest on Web security and areas such as HTML5, JavaScript, Web browsers, social networking platforms etc. He is a regular blogger and speaker at technical events. For his contributions to technical communities, he has been awarded Microsoft MVP award for 3 consecutive years-ASP.NET MVP(2010) and Internet Explorer MVP (2011, 2012). He is also pursuing M.S by Research at IIIT-Hyd with focus on security aspects of the modern web. When not at work he practices Yoga and plays Chess.


February 25, 2012

Date & Time: Saturday, February 25, 2012 at 11:00 AM .

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Agenda:

How to find zero days in web applications by Imran & Raghunath


Speakers

Mohammed Imran

Imran works as Application Security Researcher at Tata consultancy services,leads the Null Hyderabad chapter and is the Board member of OWASP Hyderabad Chapter. Apart from his day job he contributes to matriux and Fedora open source projects. Imran is a CEH and his interests include application security assessment, penetration testing and code review.


Raghunath

Raghunath works as a senior security engineer at entersoft information systems private limited. His interests include web application penetration testing.


December 17, 2011

Date & Time: Saturday, at 10:30 AM .

Venue:

Hotel Sitara Grand
Road No.12, Road No.12, Banjara Hills
Hyderabad, Andhra Pradesh 500034, India


Agenda:

Cloud Security by Arshad Noor

Speakers

Arshad Noor Chief Technology Officer StrongAuth, Inc., Sunnyvale, California

Started his great profession as a senior systems designer way back in 1986 at Port Authority of Newyork and New Jersey,- Newyork and worked in Citibank - newyork as Vice President apart from Newyork Life Insurance, BASF Corporation, Sun IT ,Sun Microsystems, INC to name. Architected and built several Public Key Infrastructure (PKI) assignments for several defense, communication, medical, Banking, e-commerce, life sciences and other industries.


November 12, 2011

Date & Time: Saturday, at 10:30 AM .

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Agenda:

HP WebInspect by Rohit Tamma

Pentesting Iphone Applications By B Satish


Speakers

Rohit Tamma

Rohit Tamma (CEH) has been working as a Application security Analyst in TCS from past 2 years. His job responsibilities include Vulnerability Assessment and Penetration Testing which enabled him to acquire extensive knowledge on HP WebInspect,IBM Rational Appscan Source Edition and HP Assessment Management Platform. Recently he also gave a presentation in Null Hyderabad meet on HP WebInspect.

Satish B

Satish has been working as a web application penetration tester since 5 years. Pentested over 200 web applications during this period. Recently he got involved in reverse engineering of binaries, WLAN security and mobile application hacking. He also Performed a couple of network assessments and source code reviews. Developed a compiler in the early stage of the career. He has a Bachelor’s Degree in Computer Science from JNTU, Hyderabad.Passionate about hacking and sharing knowledge.


20th August 2011

Date & Time: Saturady, at 11 AM

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Agenda:

Oracle Padding Attack by B. Satish

Open SAM part II by Sripati MS

Speakers

B Satish

I have been working as a web application penetration tester since 5 years. Pentested over 200 web applications during this period. Recently got involved in reverse engineering of binaries, WLAN security and mobile application hacking. Performed a couple of network assessments and source code reviews. Developed a compiler in the early stage of the career. I have a Bachelor’s Degree in Computer Science from JNTU, Hyderabad. Passionate about hacking and sharing knowledge

Sreepati M S

Sripati (http://www.sripati.info/) has little study, moderate & varied experience (dev-2 yrs., security-4+ yrs.), and lots of aspirations (as far as security goes, at least). He started his career in web-application development, then took a detour towards quality compliance for some time (~6 months) and later moved to security compliance. Still learning the ropes, he believes there is so much to learn and so little time! Interested in web-app security (as if ISMS implementation is not enough), so that says something about his guts! He thinks OWASP is a very good platform for web-app people, and that since he joined OWASP, he has learnt a lot from people around him


July 2011

Date: 23/07/2011 saturady of at 12:00 Noon .

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Agenda:

Presentation on Burp Suite by Omair
Seminar on Open SAM by Sreepati

Speakers

Sreepati M S

Sripati (http://www.sripati.info/) has little study, moderate & varied experience (dev-2 yrs., security-4+ yrs.), and lots of aspirations (as far as security goes, at least). He started his career in web-application development, then took a detour towards quality compliance for some time (~6 months) and later moved to security compliance. Still learning the ropes, he believes there is so much to learn and so little time! Interested in web-app security (as if ISMS implementation is not enough), so that says something about his guts! He thinks OWASP is a very good platform for web-app people, and that since he joined OWASP, he has learnt a lot from people around him


Omair

Omair works as penetration tester in NII consulting, has over 5 years of experience in Penetration testing. His interests include Network Penetration testing, Exploit generation and Reverse engineering


Facility Sponsor & Refreshment sponsor

3i Infotech

3i Infotech.png



june 2011

Meet on: 11/06/2011 saturday

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Facility Sponsor & Refreshment sponsor

Cognizant Technology Solutions


Cognizant.png


May 2011

Meet on: 07/05/2011 saturday

Venue:

Cognizant Technology Solutions,
3rd floor, Phase 2,
DLF Building,
APHB Colony,Gachibowli,Hyderabad

Agenda:

XSS Autopsy and w3af by Imran


Speakers

Mohammed Imran

Imran works as Application Security Researcher at Tata consultancy services,leads the Null Hyderabad chapter and is the Board member of OWASP Hyderabad Chapter. Apart from his day job he contributes to matriux and Fedora open source projects. Imran is a CEH and his interests include application security assessment, penetration testing and code review.


Sponsor

Cognizant Technology Solutions



Audio/Video/Slides Archive

<paypal>Hyderabad</paypal>