Difference between revisions of "New Jersey"

From OWASP
Jump to: navigation, search
m
(45 intermediate revisions by 3 users not shown)
Line 1: Line 1:
{{Chapter Template|chaptername=NY/NJ |extra= | mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-newjersey|emailarchives=http://lists.owasp.org/pipermail/owasp-newjersey}} 
+
= OWASP New Jersey =
  
==[http://www.globalsecurityweek.com/index.html GLOBAL INFORMATION SECURITY WEEK]==
+
<h2>[http://www.meetup.com/OWASP-New-Jersey https://www.owasp.org/images/8/82/Meetup_logo3.jpg] [http://www.meetup.com/OWASP-New-Jersey New Jersey Chapter] [http://www.meetup.com/OWASP-New-Jersey Click Here More Info]</h2>
OWASP supports Global Security Week. The next NY/NJ OWASP Chapter meeting will be on <b> <u>September 6th 5:30pm-9:00pm </u></b>
+
  
===LOCATION SPONSOR: American Stock and Options Exchange (AMEX)  ===
 
<b>Meeting Address:</b> 86 Trinity Place, NY NY 10006 ~ [http://tinyurl.com/2c5ohu Directions]
 
  
<b>Event Co-Sponsors:</b> <TBD>, <TBD>, <TBD>, <TBD>
+
<headertabs />  
  
<b>Event Speakers:</b>
+
<hr>
<br>
+
<h2>Software Security Training </h2>
Keynote: TBD
+
<br>
+
Speaker: TBD
+
<br>
+
Speaker: TBD
+
<br>
+
Speaker: TBD
+
<br>
+
  
<center><b> Meetings are FREE and open to the PUBLIC - </b>[http://fs7.formsite.com/OWASP/form185804020/index.html RSVP IS REQUESTED] </center>
+
When:
 +
Wednesday, March 13, 2013 - Thursday, March 14, 2013
 +
9:00 AM - 5:00 PM
 +
Eastern Time Zone
  
---
+
 
 +
Where:
 +
Hotel Pennsylvania
 +
401 7th Avenue
 +
Between 32nd and 33rd Streets
 +
New York, New York 10001
  
TOPIC: <b>TBD</b>
 
  
SPEAKER BIO:  TBD
+
<h3> Application Cryptanalysis Made Easy (1 Day Training)</h3>
--
+
  
TOPIC: <b>TBD</b>
+
Use of cryptography permeates today's computing infrastructures.  While few programmers attempt to implement sophisticated cryptosystems, many unwittingly develop simple protocols in every day applications without adequate knowledge of how cryptographic primitives should be combined. In this training we explore several techniques for analyzing and breaking the kinds of cryptographic protocols which are commonly found in modern applications.
  
SPEAKER BIO: TBD
+
Attendees will first be presented with a brief review of cryptographic primitives and their uses, followed by an introduction of several techniques to analyze cryptographic systems in a black-box manner. In each case, the discussion will describe how programmers can avoid making the common mistakes that allow these attacks to succeed.
--
+
  
TOPIC: <b>TBD</b>
+
Register Online to Secure Your Seat http://www.cvent.com/d/3cq429 Space is Limited! Course syllabus: https://docs.google.com/folder/d/0B-IjCXl19haHSFR6NXJTdk5uTE0/edit
  
SPEAKER BIO: TBD
+
<h3> Hack Your Own Code: Advanced Training for Developers (2 Day Training Course)</h3>
  
To submit educational topic for upcoming meeting please provide submit your powerpoint using the [http://www.owasp.org/images/5/54/Presentation_template.ppt OWASP Template] and include a speaker BIO. If you wish to become a sponsor or co-sponsor please click on one of the below email addresses of our active board members.
+
This class provides developers an exciting chance to hone their programming skills while also learning to exploit common web vulnerabilities. Unlike most training, this will not use static demos based on pre-canned source code. Students will program small parts of a larger application during the class’s lab periods. After the component has been written, students will review the code for the vulnerability being focused on in the lab. Vulnerable code will be run on a class-accessible server while the instructor guides students through exploiting the vulnerabilities. After the vulnerability is exploited, students will be shown how their own code can be fixed (if it was vulnerable) and the best way to prevent the flaw in the first place.
  
= NY/NJ OWASP Chapter Leaders =
+
This full process will be performed for all major code vulnerabilities in the OWASP Top Ten. Exploitation and patching labs (but not programming) will be held for other vulnerabilities, including logic flaws that are hard to represent on the Top Ten. Several labs will feature prizes for the students that first find or exploit the targeted vulnerability. Environments and examples will be setup for all major platforms requested by pre-registered students. Students should bring a laptop with them, preferably with VMWare Player already installed. A virtual machine based on the OWASP Live Boot CD will be provided for lab work. The virtual machine will include development tools, but students should feel free to bring their favorite programs too.
<ul>
+
Officers
+
*<b>President:</b> [mailto:jinxpuppy(at)gmail.com Tom Brennan]
+
*<b>Vice President:</b> [mailto:peter.perfetti(at)abnamro.com Pete Perfetti]
+
*<b>Secretary:</b> [mailto:santoniewicz(at)net2s.com Steve Antoniewicz]
+
*<b>Treasurer:</b> [mailto:tom.ryan(at)providesecurity.com Tom Ryan]
+
Board of Directors
+
*<b>Board Member:</b> [mailto:mdontamsetti(at)gmail.com Mahi Dontamsetti]
+
*<b>Board Member:</b> [mailto:pstern100(at)gmail.com Peter Stern]
+
*<b>Board Member:</b> [mailto:KReiter(at)insidefsi.net Kevin Reiter]
+
*<b>Board Member:</b> [mailto:BrianPei(at)yahoo.com Brian Peister]
+
*<b>Board Member:</b> [mailto:douglas.shin(at)amex.com Douglas Shin]
+
Educational Advisors
+
*<b>New Jersey Institute of Technology:</b> [mailto:oe2(at)njit.edu Osama Eljabiri]
+
*<b>Polytechnic University:</b> [mailto:memon(at)poly.edu Nasir Memon]
+
</ul>
+
  
 +
Register Online to Secure Your Seat http://www.cvent.com/d/3cq429 Space is Limited! Course syllabus: https://docs.google.com/folder/d/0B-IjCXl19haHSFR6NXJTdk5uTE0/edit
  
The chapter mailing address is:
+
<h3> Securing Mobile Devices and Applications (2 Day Training Course)</h3>
  
NY/NJ Metro OWASP
+
Mobile applications enable new threats and attacks which introduce significant risks to the enterprise, and many custom applications contain significant vulnerabilities that are unknown to the team that developed them. Considering the number of mobile applications available in the Google Play and Apple AppStore is nearing 1.5 million and vulnerabilities are skyrocketing it is imperative to perform typical application security practices. But, how is mobile different?
759 Bloomfield Ave #172
+
 
West Caldwell, New Jersey 07006
+
This two-day, hands-on course enables students to understand how easily mobile devices and applications can be successfully attacked. They will learn how to identify, avoid and remediate common vulnerabilities by walking through a threat analysis and learning critical security areas such as those identified in the OWASP Top Ten Mobile Risks and Controls. Using state-of-the-art testing tools, students will learn how to secure mobile devices across the enterprise. Students will be able to choose from iOS or Android hands-on labs throughout the course, while they learn how easily the bad guy can compromise applications and the data they contain.
 +
 
 +
Register Online to Secure Your Seat http://www.cvent.com/d/3cq429 Space is Limited! Course syllabus: https://docs.google.com/folder/d/0B-IjCXl19haHSFR6NXJTdk5uTE0/edit
 +
 
 +
***
 +
 
 +
Pricing:
 +
 
 +
1 Day Course: $750 / 2 Day Course: $1,500
 +
 
 +
***
 +
 
 +
<hr>
 +
Who are the active chapter members that are helping to build a robust chapter in 2012?
 +
 
 +
NJ = http://www.meetup.com/OWASP-New-Jersey/members/?op=leaders
 +
 
 +
[[Category:OWASP Chapter]]

Revision as of 08:09, 13 February 2013

Contents

OWASP New Jersey

Meetup_logo3.jpg New Jersey Chapter Click Here More Info



Software Security Training

When: Wednesday, March 13, 2013 - Thursday, March 14, 2013 9:00 AM - 5:00 PM Eastern Time Zone


Where: Hotel Pennsylvania 401 7th Avenue Between 32nd and 33rd Streets New York, New York 10001


Application Cryptanalysis Made Easy (1 Day Training)

Use of cryptography permeates today's computing infrastructures. While few programmers attempt to implement sophisticated cryptosystems, many unwittingly develop simple protocols in every day applications without adequate knowledge of how cryptographic primitives should be combined. In this training we explore several techniques for analyzing and breaking the kinds of cryptographic protocols which are commonly found in modern applications.

Attendees will first be presented with a brief review of cryptographic primitives and their uses, followed by an introduction of several techniques to analyze cryptographic systems in a black-box manner. In each case, the discussion will describe how programmers can avoid making the common mistakes that allow these attacks to succeed.

Register Online to Secure Your Seat http://www.cvent.com/d/3cq429 Space is Limited! Course syllabus: https://docs.google.com/folder/d/0B-IjCXl19haHSFR6NXJTdk5uTE0/edit

Hack Your Own Code: Advanced Training for Developers (2 Day Training Course)

This class provides developers an exciting chance to hone their programming skills while also learning to exploit common web vulnerabilities. Unlike most training, this will not use static demos based on pre-canned source code. Students will program small parts of a larger application during the class’s lab periods. After the component has been written, students will review the code for the vulnerability being focused on in the lab. Vulnerable code will be run on a class-accessible server while the instructor guides students through exploiting the vulnerabilities. After the vulnerability is exploited, students will be shown how their own code can be fixed (if it was vulnerable) and the best way to prevent the flaw in the first place.

This full process will be performed for all major code vulnerabilities in the OWASP Top Ten. Exploitation and patching labs (but not programming) will be held for other vulnerabilities, including logic flaws that are hard to represent on the Top Ten. Several labs will feature prizes for the students that first find or exploit the targeted vulnerability. Environments and examples will be setup for all major platforms requested by pre-registered students. Students should bring a laptop with them, preferably with VMWare Player already installed. A virtual machine based on the OWASP Live Boot CD will be provided for lab work. The virtual machine will include development tools, but students should feel free to bring their favorite programs too.

Register Online to Secure Your Seat http://www.cvent.com/d/3cq429 Space is Limited! Course syllabus: https://docs.google.com/folder/d/0B-IjCXl19haHSFR6NXJTdk5uTE0/edit

Securing Mobile Devices and Applications (2 Day Training Course)

Mobile applications enable new threats and attacks which introduce significant risks to the enterprise, and many custom applications contain significant vulnerabilities that are unknown to the team that developed them. Considering the number of mobile applications available in the Google Play and Apple AppStore is nearing 1.5 million and vulnerabilities are skyrocketing it is imperative to perform typical application security practices. But, how is mobile different?

This two-day, hands-on course enables students to understand how easily mobile devices and applications can be successfully attacked. They will learn how to identify, avoid and remediate common vulnerabilities by walking through a threat analysis and learning critical security areas such as those identified in the OWASP Top Ten Mobile Risks and Controls. Using state-of-the-art testing tools, students will learn how to secure mobile devices across the enterprise. Students will be able to choose from iOS or Android hands-on labs throughout the course, while they learn how easily the bad guy can compromise applications and the data they contain.

Register Online to Secure Your Seat http://www.cvent.com/d/3cq429 Space is Limited! Course syllabus: https://docs.google.com/folder/d/0B-IjCXl19haHSFR6NXJTdk5uTE0/edit

Pricing:

1 Day Course: $750 / 2 Day Course: $1,500


Who are the active chapter members that are helping to build a robust chapter in 2012?

NJ = http://www.meetup.com/OWASP-New-Jersey/members/?op=leaders