Difference between revisions of "Omaha"

From OWASP
Jump to: navigation, search
(Undo revision 177000 by Rob Temple (talk))
 
(40 intermediate revisions by one user not shown)
Line 1: Line 1:
{{Chapter Template|chaptername=Omaha|extra=The chapter leaders are [mailto:rob.temple@owasp.org Rob Temple].
+
{{Chapter Template|chaptername=Omaha|extra=The chapter leaders are [mailto:john.rogers@owasp.org John Rogers], [mailto:zac.fowler@owasp.org Zac Fowler], [mailto:rob.temple@owasp.org Rob Temple], Fred Donovan, and [mailto:micae.born@owasp.org Michael Born].
 +
 
 
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-omaha|emailarchives=http://lists.owasp.org/pipermail/owasp-omaha}}
 
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-omaha|emailarchives=http://lists.owasp.org/pipermail/owasp-omaha}}
  
Line 5: Line 6:
 
    
 
    
  
==Local News ==
+
== Chapter Meetings ==
  
'''Meeting Location'''
+
Everyone is welcome to join us at our chapter meetings!
 
+
Everyone is welcome to join us at our chapter meetings.
+
  
 
Follow us on Twitter!  https://www.twitter.com/owaspomaha
 
Follow us on Twitter!  https://www.twitter.com/owaspomaha
----
 
  
----
+
Typically, we meet at UNO's Peter Kiewit Institute over the noon hour during the last month of each quarter.
<br/>
+
 
OWASP OMAHA 2013 Presentation and Chapter Meeting Schedule:
+
We also use Google+ Hangouts OnAir to stream our presentations live!
<br/>
+
 
<br/>
+
 
 +
== Past Events ==
 
 
Thu Mar 7, 2013 - '''Welcome to OWASP Omaha!'''
+
=== Thu Mar 7, 2013 - '''Welcome to OWASP Omaha!''' ===
 
<br/>-Presenters, OWASP Omaha Chapter Leadership
 
<br/>-Presenters, OWASP Omaha Chapter Leadership
 
<br/>-Thursday, March 7th, 12:00 noon - 1:00 P.M., Bellevue University
 
<br/>-Thursday, March 7th, 12:00 noon - 1:00 P.M., Bellevue University
 +
<br/>-Durham Student Center (building #6). Park in Lot D.  Check out the map here: [http://www.bellevue.edu/about/content/images/map-of-main-campus.jpg]. 
 +
<br/>-Meet the chapter leaders and learn more about OWASP Omaha
 +
<br/>
 
 
Thu Jun 6, 2013 - '''Mobile App Security'''
+
=== Thu Jun 6, 2013 - '''Web Application Security - So many tools, so little time'''===
<br/>-Presenter, John M. Rogers, Senior Application Security Engineer, Lincoln Financial Group
+
<br/>Presenter, John M. Rogers, Senior Application Security Engineer, Lincoln Financial Group
<br/>-Time & Location, TBA
+
 
 +
This talk focuses on the first three candidates of the 2013 OWASP Top 10. John will demonstrate attack examples, common tools to find these flaws, and consequences that occur without remediation or mitigating controls.
 +
 
 +
John Rogers is a Senior Application Security Engineer working in the Security Assurance department at Lincoln Financial Group.  Previously John worked as a Lead Security Engineer at ACI Worldwide, Inc.  John is one of the unique Application Security Professionals with over 20 years of experience in all aspects of the Software Development Lifecycle (SDLC) for the Banking, Payment and Financial Services industries.  John is also a Certified Information Systems Security Professional (CISSP) and serves as President of InfraGard Nebraska
 +
 
 +
 
 +
Time & Location: Thursday, June 6, 12PM.  Peter Kiewit Institute, Room 279.  (67th and Pacific in Omaha)
 +
RSVP and view more details on our EventBrite page: https://www.eventbrite.com/event/6952516163
 +
 
 +
 
 +
 
 
 
Thu Sep 5, 2013 - '''The OWASP Way: Understanding the OWASP Vision and the Top Ten'''
+
=== Thu Sep 12, 2013 - '''The OWASP Way: Understanding the OWASP Vision and the Top Ten''' ===
<br/>-Presenter,  Scott Christiansen, Software Security Engineer, TD Ameritrade
+
<br/>Presenter,  Scott Christiansen, Software Security Engineer, TD Ameritrade
<br/>-Time & Location, TBA
+
 
 +
<p>
 +
Scott a Software Security Engineer for TD Ameritrade.  In this role he provides static and dynamic application assessments for over 250 TD Ameritrade front end, back end and mobile applications.  Prior to this Scott was the Lead Analyst for TD Ameritrade’s Security Event Center which coordinates incident response within TD Ameritrade.  In addition to this Scott is also an Adjunct Instructor for ITT Technical Institute’s Bachelors of Information Security program, and an adjunct Professor for Bellevue University’s Masters of Cyber Security Program.  Prior to his current role with Scott was the Chief Security Officer for the Leo A Daly Company.  Scott is also a Past President of Nebraska InfraGard, and a graduate of the FBI Citizen’s Academy.  Scott received his Bachelor’s Degree in 2003 from Bellevue University in Business Information Systems and his Master’s Degree from the University of Nebraska Omaha in the Management of Information Systems.  Upon Graduation Scott was the recipient of the 2007-2008 Outstanding Graduate Student in Information Systems & Quantitative Analysis.  Scott is a current CISSP holder in addition to numerous other certification’s from CompTIA and Microsoft.
 +
 
 +
</p>
 +
 
 +
Time & Location: Thursday, Sept 12th, 12PM.  TriPointe Coffeehouse, http://tripointecoffeehouse.com/, 138 N. Washington Street  Papillion, NE 68046
 +
 
 +
[https://www.owasp.org/images/4/40/OWASP_Vision_and_Top_Ten_-_Sept_12_-_Scott_Christiansen.pptx Download Scott's Slides]
 +
 
 
 
Thu Dec 5, 2013 - '''Advanced Web & Mobile Penetration Testing'''  
+
=== Thu Dec 5, 2013 - '''Mobile Application Security Assessments''' ===
<br/>-Presenter, Tristan Lawson, Senior Security Consultant, Continuum Security Solutions
+
<br/>Presenter, Michael Born, Solutionary
<br/>-Time & Location, TBA
+
<p>
<br/>
+
As the world becomes increasingly more 'connected', our digital lives get transmitted through various types of applications including mobile devices. Besides that, the bring your own device debate among security professionals within corporate enterprise environments, maintaining confidentiality, availability, and integrity of data transmitted through these devices must be a continued focus of the security community.
<br/>
+
</p>
 +
<p>In this presentation, Michael Born, an Associate Security Consultant with Solutionary will walk through a step by step demonstration of setting up and performing a mobile application security assessment on both Android and iOS. Included in the presentation will be an example iOS Security Assessment performed by Michael along with a hands on walk through of a Jailbroken iOS device file system.
 +
</p>
 +
<p>Check out a warm-up video at our youtube channel: http://www.youtube.com/watch?v=VRnj816ec-8. This video walks through some set up step so that we're on the same page for the presentation!</p>
 +
<br/>-Peter Kiewit Institute, 1110 S. 67th Street, Omaha, NE 68182, Room 279.  12:00 - 1:00 PM. The room will open at 11:45AM.
 +
<br/>-Pizza will be provided on a first-come first-serve basis
 +
<br/>-UNO has open parking that week, so you will not need to worry about obtaining a pass.
 +
 
 +
RSVP on EventBrite</b> at http://www.eventbrite.com/e/mobile-application-security-assessments-tickets-9326244047?aff=eorg
 
----
 
----
  
 
----
 
----
  
+
===  Thu Mar 13, 2014 - '''Vetting Third Party Vendor Applications''' ===
 +
Presenter: John Rogers<br>
 +
This presentation will discuss how to acquire and validate information that will provide assurance that your third party vendor applications adhere to your standards and are free from the common web application vulnerabilities.  The discussion will also include what basic requirements are needed to accept a web application security assessment report from an independent security assessment firm.
 +
<br>
 +
<bR>
 +
John will hit points covering:
 +
<br>
 +
- 3rd Party Vendor Assessment Requirements
 +
- 3rd Party Vendor Assessment Public Facing Document
 +
- 3rd Party Vendor Application Security Standards
 +
 
 +
 
 +
'''Location''': -Peter Kiewit Institute, 1110 S. 67th Street, Omaha, NE 68182, Room 350.  <br>
 +
'''Time''': 12:00 - 1:00 PM. The room will open at 11:45AM.<br>
 +
 
 +
<b>RSVP on EventBrite</b> at https://www.eventbrite.com/e/vetting-third-party-vendor-applications-tickets-9617944531 </b>
 +
 
 +
'''Parking''': Email zac.fowler@owasp.org for a parking pass for the talk.  **A copy was attached on the reminder sent to OWASP Omaha mailing list -- check your inbox.
 +
 
 +
'''Screencast''': Google+ Hangout link will be posted prior to start via OWASP Omaha mailing list and twitter feed.  Here's the link: http://youtu.be/Z5gcT53Wydc
 +
 
 +
""Files"": You can download the files from this presentation here: https://drive.google.com/folderview?id=0B4t_HSHrO2GxZ1N6OUxVYXE2Q2M&usp=sharing
 +
 
 +
 
 +
 +
=== Sat Mar 29 2014 - '''Web Application Security - So many tools, so little time Redux'''===
 +
<br/>Presenter, John M. Rogers, Senior Application Security Engineer, Lincoln Financial Group
 +
 
 +
Location: Nebraska Code Camp 2014
 +
 
 +
This talk focuses on the first three candidates of the 2013 OWASP Top 10. John will demonstrate attack examples, common tools to find these flaws, and consequences that occur without remediation or mitigating controls.
 +
 
 +
John Rogers is a Senior Application Security Engineer working in the Security Assurance department at Lincoln Financial Group.  Previously John worked as a Lead Security Engineer at ACI Worldwide, Inc.  John is one of the unique Application Security Professionals with over 20 years of experience in all aspects of the Software Development Lifecycle (SDLC) for the Banking, Payment and Financial Services industries.  John is also a Certified Information Systems Security Professional (CISSP) and serves as President of InfraGard Nebraska
 +
 
 +
'''Note:''' This is a talk at the Nebraska Code Camp - http://nebraskacodecamp.com
 +
 
 +
 
 +
 
 +
=== Thu June 12, 2014 - '''OWASP in Payment Card Security:  Secure Coding, OWASP, and PCI 3.0 DSS Requirement 6''' ===
 +
 
 +
Presented by Rob Temple, Joel vanBrandwijk, and Ryan Misek from Mutual of Omaha
 +
 
 +
Data breaches and payment card compromises are more frequent, high-profile, and damaging.  The every day consumer has been hit by large data breaches at Target, Michaels, and Aaron Brothers, among others.  People all around us can testify to the effects of millions of credit cards in the wrong hands.  It has become commonplace.
 +
 
 +
The PCI Security Standards Council (PCI SSC) security standards has recently released a new and improved set of requirements and standards for any organization that processes, transmits, or stores payment card data.  PCI DSS' infamous Requirement 6 focuses on secure systems and applications, including secure coding and web application firewalls.  OWASP has been noted in the PCI DSS as a trusted resource for secure coding and application vulnerability management.  Join us for our next OWASP Omaha chapter meeting as we explore the some of these resources and discuss ways that OWASP can help meet this requirement.
 +
 
 +
Rob Temple is an information security analyst with Mutual of Omaha.  He has been a software solutions developer for over 15 years working primarily with the.NET/Java languages.  His recent web app projects include security based tools in the identity management space.  Prior to Mutual of Omaha, Rob worked as an infosec consultant, performing PCI DSS and HIPAA security assessments for financial institutions and higher education organizations.  He also has experience with web application pentesting and appsec consulting.  Rob initiated the reactivation of the OWASP Omaha Chapter with the encouragement of OWASP Executive Director, Sarah Baso in 2011,  He currently serves as a member of the leadership team.
 +
 
 +
'''Location''': The Peter Kiewit Institute, Univ. of Nebraska at Omaha's Pacific Street Campus, 1110 S. 67th Street, Omaha, NE 68182, Room **164**.  <br>
 +
'''Time''': 12:00 - 1:00 PM. The room will open at 11:45AM.<br>
 +
'''RSVP for Food Counts''': https://www.eventbrite.com/e/owasp-in-payment-card-security-secure-coding-owasp-pci-30-dss-req-6-tickets-11741110979'''<br>
 +
'''Parking and lunch''': Pizza will be provided by the College of IS&T (so please RSVP).  Contact zac dot fowler at owasp dot org if you need a parking pass.<br>
 +
'''Google+ Hangout''': Watch the video here: https://www.youtube.com/watch?v=oe2ngtR2mJU
 +
 
 +
Slides available here: https://drive.google.com/folderview?id=0B4t_HSHrO2GxRHpDc2tGZ2szZUk&usp=sharing
  
  
  
 +
== Upcoming Events ==
  
 +
There are no scheduled events at this time.
  
 
[[Category:Nebraska]]
 
[[Category:Nebraska]]
  
 
[[Category:OWASP Chapter|Omaha]]
 
[[Category:OWASP Chapter|Omaha]]

Latest revision as of 16:55, 16 June 2014

Contents

OWASP Omaha

Welcome to the Omaha chapter homepage. The chapter leaders are John Rogers, Zac Fowler, Rob Temple, Fred Donovan, and Michael Born.
Click here to join the local chapter mailing list.

Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is and open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter.

Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG



Chapter Meetings

Everyone is welcome to join us at our chapter meetings!

Follow us on Twitter! https://www.twitter.com/owaspomaha

Typically, we meet at UNO's Peter Kiewit Institute over the noon hour during the last month of each quarter.

We also use Google+ Hangouts OnAir to stream our presentations live!


Past Events

Thu Mar 7, 2013 - Welcome to OWASP Omaha!


-Presenters, OWASP Omaha Chapter Leadership
-Thursday, March 7th, 12:00 noon - 1:00 P.M., Bellevue University
-Durham Student Center (building #6). Park in Lot D. Check out the map here: [1].
-Meet the chapter leaders and learn more about OWASP Omaha

Thu Jun 6, 2013 - Web Application Security - So many tools, so little time


Presenter, John M. Rogers, Senior Application Security Engineer, Lincoln Financial Group

This talk focuses on the first three candidates of the 2013 OWASP Top 10. John will demonstrate attack examples, common tools to find these flaws, and consequences that occur without remediation or mitigating controls.

John Rogers is a Senior Application Security Engineer working in the Security Assurance department at Lincoln Financial Group.  Previously John worked as a Lead Security Engineer at ACI Worldwide, Inc.  John is one of the unique Application Security Professionals with over 20 years of experience in all aspects of the Software Development Lifecycle (SDLC) for the Banking, Payment and Financial Services industries.  John is also a Certified Information Systems Security Professional (CISSP) and serves as President of InfraGard Nebraska


Time & Location: Thursday, June 6, 12PM. Peter Kiewit Institute, Room 279. (67th and Pacific in Omaha) RSVP and view more details on our EventBrite page: https://www.eventbrite.com/event/6952516163



Thu Sep 12, 2013 - The OWASP Way: Understanding the OWASP Vision and the Top Ten


Presenter, Scott Christiansen, Software Security Engineer, TD Ameritrade

Scott a Software Security Engineer for TD Ameritrade.  In this role he provides static and dynamic application assessments for over 250 TD Ameritrade front end, back end and mobile applications.  Prior to this Scott was the Lead Analyst for TD Ameritrade’s Security Event Center which coordinates incident response within TD Ameritrade.  In addition to this Scott is also an Adjunct Instructor for ITT Technical Institute’s Bachelors of Information Security program, and an adjunct Professor for Bellevue University’s Masters of Cyber Security Program.  Prior to his current role with Scott was the Chief Security Officer for the Leo A Daly Company.  Scott is also a Past President of Nebraska InfraGard, and a graduate of the FBI Citizen’s Academy.  Scott received his Bachelor’s Degree in 2003 from Bellevue University in Business Information Systems and his Master’s Degree from the University of Nebraska Omaha in the Management of Information Systems.  Upon Graduation Scott was the recipient of the 2007-2008 Outstanding Graduate Student in Information Systems & Quantitative Analysis.  Scott is a current CISSP holder in addition to numerous other certification’s from CompTIA and Microsoft.

Time & Location: Thursday, Sept 12th, 12PM. TriPointe Coffeehouse, http://tripointecoffeehouse.com/, 138 N. Washington Street Papillion, NE 68046

Download Scott's Slides


Thu Dec 5, 2013 - Mobile Application Security Assessments


Presenter, Michael Born, Solutionary

As the world becomes increasingly more 'connected', our digital lives get transmitted through various types of applications including mobile devices. Besides that, the bring your own device debate among security professionals within corporate enterprise environments, maintaining confidentiality, availability, and integrity of data transmitted through these devices must be a continued focus of the security community.

In this presentation, Michael Born, an Associate Security Consultant with Solutionary will walk through a step by step demonstration of setting up and performing a mobile application security assessment on both Android and iOS. Included in the presentation will be an example iOS Security Assessment performed by Michael along with a hands on walk through of a Jailbroken iOS device file system.

Check out a warm-up video at our youtube channel: http://www.youtube.com/watch?v=VRnj816ec-8. This video walks through some set up step so that we're on the same page for the presentation!


-Peter Kiewit Institute, 1110 S. 67th Street, Omaha, NE 68182, Room 279. 12:00 - 1:00 PM. The room will open at 11:45AM.
-Pizza will be provided on a first-come first-serve basis
-UNO has open parking that week, so you will not need to worry about obtaining a pass.

RSVP on EventBrite</b> at http://www.eventbrite.com/e/mobile-application-security-assessments-tickets-9326244047?aff=eorg



Thu Mar 13, 2014 - Vetting Third Party Vendor Applications

Presenter: John Rogers
This presentation will discuss how to acquire and validate information that will provide assurance that your third party vendor applications adhere to your standards and are free from the common web application vulnerabilities. The discussion will also include what basic requirements are needed to accept a web application security assessment report from an independent security assessment firm.

John will hit points covering:
- 3rd Party Vendor Assessment Requirements - 3rd Party Vendor Assessment Public Facing Document - 3rd Party Vendor Application Security Standards


Location: -Peter Kiewit Institute, 1110 S. 67th Street, Omaha, NE 68182, Room 350.
Time: 12:00 - 1:00 PM. The room will open at 11:45AM.

RSVP on EventBrite at https://www.eventbrite.com/e/vetting-third-party-vendor-applications-tickets-9617944531 </b>

Parking: Email zac.fowler@owasp.org for a parking pass for the talk. **A copy was attached on the reminder sent to OWASP Omaha mailing list -- check your inbox.

Screencast: Google+ Hangout link will be posted prior to start via OWASP Omaha mailing list and twitter feed. Here's the link: http://youtu.be/Z5gcT53Wydc

""Files"": You can download the files from this presentation here: https://drive.google.com/folderview?id=0B4t_HSHrO2GxZ1N6OUxVYXE2Q2M&usp=sharing


Sat Mar 29 2014 - Web Application Security - So many tools, so little time Redux


Presenter, John M. Rogers, Senior Application Security Engineer, Lincoln Financial Group

Location: Nebraska Code Camp 2014

This talk focuses on the first three candidates of the 2013 OWASP Top 10. John will demonstrate attack examples, common tools to find these flaws, and consequences that occur without remediation or mitigating controls.

John Rogers is a Senior Application Security Engineer working in the Security Assurance department at Lincoln Financial Group.  Previously John worked as a Lead Security Engineer at ACI Worldwide, Inc.  John is one of the unique Application Security Professionals with over 20 years of experience in all aspects of the Software Development Lifecycle (SDLC) for the Banking, Payment and Financial Services industries.  John is also a Certified Information Systems Security Professional (CISSP) and serves as President of InfraGard Nebraska

Note: This is a talk at the Nebraska Code Camp - http://nebraskacodecamp.com


Thu June 12, 2014 - OWASP in Payment Card Security: Secure Coding, OWASP, and PCI 3.0 DSS Requirement 6

Presented by Rob Temple, Joel vanBrandwijk, and Ryan Misek from Mutual of Omaha

Data breaches and payment card compromises are more frequent, high-profile, and damaging. The every day consumer has been hit by large data breaches at Target, Michaels, and Aaron Brothers, among others. People all around us can testify to the effects of millions of credit cards in the wrong hands. It has become commonplace.

The PCI Security Standards Council (PCI SSC) security standards has recently released a new and improved set of requirements and standards for any organization that processes, transmits, or stores payment card data. PCI DSS' infamous Requirement 6 focuses on secure systems and applications, including secure coding and web application firewalls. OWASP has been noted in the PCI DSS as a trusted resource for secure coding and application vulnerability management. Join us for our next OWASP Omaha chapter meeting as we explore the some of these resources and discuss ways that OWASP can help meet this requirement.

Rob Temple is an information security analyst with Mutual of Omaha. He has been a software solutions developer for over 15 years working primarily with the.NET/Java languages. His recent web app projects include security based tools in the identity management space. Prior to Mutual of Omaha, Rob worked as an infosec consultant, performing PCI DSS and HIPAA security assessments for financial institutions and higher education organizations. He also has experience with web application pentesting and appsec consulting. Rob initiated the reactivation of the OWASP Omaha Chapter with the encouragement of OWASP Executive Director, Sarah Baso in 2011, He currently serves as a member of the leadership team.

Location: The Peter Kiewit Institute, Univ. of Nebraska at Omaha's Pacific Street Campus, 1110 S. 67th Street, Omaha, NE 68182, Room **164**.
Time: 12:00 - 1:00 PM. The room will open at 11:45AM.
RSVP for Food Counts: https://www.eventbrite.com/e/owasp-in-payment-card-security-secure-coding-owasp-pci-30-dss-req-6-tickets-11741110979
Parking and lunch: Pizza will be provided by the College of IS&T (so please RSVP). Contact zac dot fowler at owasp dot org if you need a parking pass.
Google+ Hangout: Watch the video here: https://www.youtube.com/watch?v=oe2ngtR2mJU

Slides available here: https://drive.google.com/folderview?id=0B4t_HSHrO2GxRHpDc2tGZ2szZUk&usp=sharing


Upcoming Events

There are no scheduled events at this time.