Welcome to the NY/NJ chapter homepage.
Click here to join the local chapter mailing list.
OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.
Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member?
SEPTEMBER 6th MEETING
OWASP supports Global Security Week (Sept. 3rd-9th) Click Here More Info.... In local support of this worldwide effort, the next NY/NJ OWASP Chapter meeting will be on September 6th 5:30pm-9:00pm
PRIMARY SPONSOR: AMERICAN STOCK EXCHANGE
Special thanks to OWASP Board Member: Doug Shin of the AMEX Meeting Address: 86 Trinity Place, NY NY 10006 ~ Directions
TOPIC: Global Security Week Working Group What is the current state of Privacy on Web Application Security? What should we be focusing on?
Panel Leader: Tom Brennan GSW
TOPIC: Why today's vulnerability assessments are failing and a case for industry standardization
As organizations mature their information security capabilities they start to extend their requirements to their partners and providers. Providing for the identification and management of information security issues are becoming part of contractual language. Vulnerability Assessment / ethical reports today are used today as one measurable data point to build a confidence in the status of other parties’ web applications and is generally an accepted set in due diligence. The challenge today is these Vulnerability Assessments are inconsistent in scope & rigor, and reported in a form that makes them incomparable between institutions. It is frequently impossible to understand what test design was used (black box/white box), what set of conditions were tested (OWASP top ten only, CVE, items found by common scanning tools, manually exercised conditions, etc) and how issues were rated for severity (CVSS, vendor provided, customer provided, etc). A similar problem existed with information security assessments of operational and physical security at outsourced service providers used by financial institutions and was address by developing an “agreed upon procedures” approach to outline common things needed by institutions so that assessments could be done once by a neutral party and then reused. This presentation, while not offering the complete answer for application security testing, will attempt to outline the components needed for such a solution.
SPEAKER BIO: Mark Clancy is Senior Vice President at Citigroup
TOPIC: Hackers...BotNets oh My! FBI Cybercrimes task force to discuss global status of BotNets.
SPEAKER BIO: Chris Stangel NYC FBI Cyber Crime Unit
TOPIC: OWASP Project JBroFuzz: Fuzzing for Network and Web Applications
JBroFuzz is a OWASP stateless network protocol fuzzer that emerged from the needs of penetration testing. This presentation will aim to illustrate efficient ways of fuzzing in order to minimize the amount of time spent in discovering application and network protocol vulnerabilities.
SPEAKER: Dr. Yiannis Pavlosoglou is a Security Project Manager at Information Risk Management
TOPIC: Stock fluctuation from an unrecognized influence.
SPEAKER: Justine Bone - Aitel - Immunity Security
OCTOBER 25th MEETING
Full Day, information security summit happening in New Jersey on October 25th. At this all day event, learn from industry experts on topics of information security. There is no charge for this event. October 25th 9:30am-4:30pm
PRIMARY SPONSOR: VERIZON WIRELESS
Special thanks to: Philip Varughese Meeting Address: 295 N Maple Ave, Basking Ridge, NJ 07920 ~ Directions
SPEAKER: Renato Delatorre, Verizon Wireless
TOPIC: Social Engineering
SPEAKER: Kevin Mitnick
TOPIC: ISO 27001 What is it... Why do you care?
SPEAKER BIO: Mahi Dontamsetti
TOPIC: VOIP - Can you hear me now?
SPEAKER BIO: Paul Rohmeyer
TOPIC: Internet Fraud - War Stories
SPEAKER BIO: Mike Esposito
TOPIC: Dig Your Own Hole: 12 Ways to Go Wrong with Java Security
SPEAKER BIO: Richard Bowen
TOPIC: IMS = Is Missing Security?
SPEAKER: Peter Thermos, Michael McCobb
SPEAKER BIO: TBD
To submit educational topic for upcoming meeting please provide submit your powerpoint using the OWASP Template and include a speaker BIO. If you wish to become a sponsor or co-sponsor please click on one of the below email addresses of our active board members.
NY/NJ OWASP Chapter Leaders
- President: Tom Brennan
- Vice President: Pete Perfetti
- Secretary: Steve Antoniewicz
- Treasurer: Tom Ryan
- Board Member: Mahi Dontamsetti
- Board Member: Peter Stern
- Board Member: Kevin Reiter
- Board Member: Brian Peister
- Board Member: Douglas Shin
The chapter mailing address is:
NY/NJ Metro OWASP
759 Bloomfield Ave #172
West Caldwell, New Jersey 07006