Difference between revisions of "Podcast 12"

From OWASP
Jump to: navigation, search
m
(OWASP AppSec News)
Line 6: Line 6:
 
==OWASP AppSec News==
 
==OWASP AppSec News==
 
Feb 10 - https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/1093-BSI.html<br/ >
 
Feb 10 - https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/1093-BSI.html<br/ >
BSI asks "What measures do vendors use for software assurance?"<br/ >
+
The Build Security In website asks "What measures do vendors use for software assurance?". Jeremy Epstein performed a study with 8 independent software vendors about their techniques and motivations for implementing an internal software assurance program similar in theory to the Microsoft SDL.<br/ >
 
Feb 11 - http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx<br />
 
Feb 11 - http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx<br />
Rafal Los of HP talks about tools<br/ >
+
Rafal Los of HP postulates that all tools and all human testers have shortcomings, demonstrated by the fact that there are so many inconsistencies in pen-testing activities.<br/ >
 
Feb 13 - http://www.cigital.com/justiceleague/2009/02/13/do-cloud-based-apps-destroy-web-app-security/<br/ >
 
Feb 13 - http://www.cigital.com/justiceleague/2009/02/13/do-cloud-based-apps-destroy-web-app-security/<br/ >
 
Feb 19 - http://nickcoblentz.blogspot.com/2009/02/create-security-strategy-before.html<br/ >
 
Feb 19 - http://nickcoblentz.blogspot.com/2009/02/create-security-strategy-before.html<br/ >
Scott Matsumoto waxes philosophical about the effect of cloud computing on web applications<br/ >
+
Scott Matsumoto waxes philosophical about the effect of cloud computing on web applications, while Nick Coblentz discusses plans for web application security integration with cloud computing.<br/ >
Nick Coblentz discusses plans for web application security integration with cloud computing<br/ >
+
 
Feb 14 - http://wivet.googlecode.com<br/ >
 
Feb 14 - http://wivet.googlecode.com<br/ >
Wivet, a benchmarking project that aims to statistically analyze web link extractors (i.e. gauge the quality of web application security scanners) recently released version 3 and updated their wiki with new information about scanner results and a future look through their wishlist<br/ >
+
Wivet, a benchmarking project that aims to statistically analyze web link extractors (that is - gauge the quality of a web application security scanner's ability to crawl) recently released version 3 and updated their wiki with new information about scanner results and a future look through their wishlist.<br/ >
 
Feb 16 - http://www.owasp.org/index.php/Cincinnati#November_Meeting<br/ >
 
Feb 16 - http://www.owasp.org/index.php/Cincinnati#November_Meeting<br/ >
The OWASP local chapter in Cincinnati has recently posted a presentation given in November 2008 by Jeremiah Blatz on "Web Application Hacking for Developers"<br/ >
+
The OWASP local chapter in Cincinnati has recently posted a presentation given in November 2008 by Jeremiah Blatz of Foundstone on "Web Application Hacking for Developers".<br/ >
 
Feb 18 - http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Smith<br/ >
 
Feb 18 - http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Smith<br/ >
The powerpoints and whitepapers for BlackHat DC 2009 were made available, including a fabulous presentation from Colin Ames, Delchi, and Val Smith on "Dissecting Web Attacks"<br/ >
+
The presentaitons and whitepapers for BlackHat DC 2009 were made available, including a fabulous presentation from Colin Ames, Delchi, and Val Smith on "Dissecting Web Attacks".<br/ >
 
Feb 15 - http://www.dragoslungu.com/2009/02/15/gartner-magic-quadrant-on-static-application-security-testing-feb-2009/<br />
 
Feb 15 - http://www.dragoslungu.com/2009/02/15/gartner-magic-quadrant-on-static-application-security-testing-feb-2009/<br />
 
Feb 20 - http://www.cigital.com/justiceleague/2009/02/19/gartner-and-static-analysis/<br/ >
 
Feb 20 - http://www.cigital.com/justiceleague/2009/02/19/gartner-and-static-analysis/<br/ >
Line 24: Line 23:
 
John Steven at Cigital weighs in with his SAST views<br/ >
 
John Steven at Cigital weighs in with his SAST views<br/ >
 
Feb 20 - http://www.securitycatalyst.com/the-balkanization-of-web-application-security/<br/ >
 
Feb 20 - http://www.securitycatalyst.com/the-balkanization-of-web-application-security/<br/ >
Bill Pennington theorizes, "most people in the web application security space are specialist in one particular area, source code review, black box testing, web application firewalls or developer training. This lack of knowledge of the other solutions generally breeds fear and contempt".<br/ >
+
Bill Pennington theorizes, "most people in the web application security space are a specialist in one particular area, source code review, black box testing, web application firewalls or developer training. This lack of knowledge of the other solutions generally breeds fear and contempt".<br/ >
 
Feb 22 - http://appsecnotes.blogspot.com/2009/02/dirbuster-shoots-and-scores.html<br/ >
 
Feb 22 - http://appsecnotes.blogspot.com/2009/02/dirbuster-shoots-and-scores.html<br/ >
Dave Ferguson discusses the OWASP DirBuster tool, developed by James Fisher<br/ >
+
Dave Ferguson discusses the OWASP DirBuster tool, developed by James Fisher.<br/ >
 
Feb 22 - http://funkatron.com/site/comments/safely-parsing-json-in-javascript/<br/ >
 
Feb 22 - http://funkatron.com/site/comments/safely-parsing-json-in-javascript/<br/ >
A discussion about safely parsing JSON in Javascript, which includes Douglas Crocker's prescriptions<br/ >
+
A discussion about safely parsing JSON in Javascript, which includes Douglas Crocker's prescriptions.<br/ >
Feb 24 - http://www.infosecramblings.com/2009/02/24/insecure-magazine-20-is-out/<br/ >
+
Feb 25 - http://shreeraj.blogspot.com/2009/02/article-on-web-2.html<br/ >
Kevin Riggins brings attention to the latest issue of INSECURE magazine, issue 20.  The recent magazine includes an article on "Web 2.0 case studies: challenges, approaches and vulnerabilities"<br/ >
+
Shreeraj Shah brings attention to the latest issue of INSECURE magazine, issue 20.  The recent magazine includes his article on "Web 2.0 case studies: challenges, approaches and vulnerabilities".<br/ >
 +
Feb 25 - http://www.owasp.org/index.php/OWASP_AU_Conference_2009<br/ >
 +
We bring you an update on the happenings at the OWASP AU Conference 2009.<br/ >
 
<br/ >
 
<br/ >
 
Society of Payment Security Professionals<br/ >
 
Society of Payment Security Professionals<br/ >
 
https://www.paymentsecuritypros.com/en/articles/search.asp?category=Articles<br/ >
 
https://www.paymentsecuritypros.com/en/articles/search.asp?category=Articles<br/ >
 
https://www.paymentsecuritypros.com/en/users/login.asp?/appsecurityusergroup/index.asp<br/ >
 
https://www.paymentsecuritypros.com/en/users/login.asp?/appsecurityusergroup/index.asp<br/ >
SPSP has recently posted information about Education and Training Validity, as well as Certification Validation.  Ed Bellis of Orbitz and Trey Ford of WhiteHatSec are heading up the AppSec working group within SPSP, but the information about the group and wiki are currently members only<br/ >
+
SPSP has recently posted information about Education and Training Validity, as well as Certification Validation.  Ed Bellis of Orbitz and Trey Ford of WhiteHatSec are heading up the AppSec working group within SPSP, but the information about the group and wiki are currently members only.<br/ >
 
<br/ >
 
<br/ >
 
Safari and GIFAR<br/ >
 
Safari and GIFAR<br/ >
Line 41: Line 42:
 
Feb 24 - http://riosec.com/updates-on-gifar-vulnerability<br/ >
 
Feb 24 - http://riosec.com/updates-on-gifar-vulnerability<br/ >
 
Feb 25 - http://www.cgisecurity.com/2009/02/apple-goes-public-with-security-in-safari-4.html<br/ >
 
Feb 25 - http://www.cgisecurity.com/2009/02/apple-goes-public-with-security-in-safari-4.html<br/ >
Billy Rios speaks about the recent Safari security bugs and GIFAR.  Robert Auger speaks to the recent security improvements upcoming in Safari version 4<br/ >
+
Billy Rios speaks about the recent Safari security bugs and GIFAR.  Robert Auger speaks to the recent security improvements upcoming in Safari version 4.<br/ >
 
<br/ >
 
<br/ >
 
OWASP Software Assurance Day 2009
 
OWASP Software Assurance Day 2009

Revision as of 18:19, 26 February 2009

OWASP Podcast Series #3

OWASP NEWS March 2009
Recording TBD

OWASP AppSec News

Feb 10 - https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/1093-BSI.html
The Build Security In website asks "What measures do vendors use for software assurance?". Jeremy Epstein performed a study with 8 independent software vendors about their techniques and motivations for implementing an internal software assurance program similar in theory to the Microsoft SDL.
Feb 11 - http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2009/02/10/an-unfortunate-case-of-learned-behavior.aspx
Rafal Los of HP postulates that all tools and all human testers have shortcomings, demonstrated by the fact that there are so many inconsistencies in pen-testing activities.
Feb 13 - http://www.cigital.com/justiceleague/2009/02/13/do-cloud-based-apps-destroy-web-app-security/
Feb 19 - http://nickcoblentz.blogspot.com/2009/02/create-security-strategy-before.html
Scott Matsumoto waxes philosophical about the effect of cloud computing on web applications, while Nick Coblentz discusses plans for web application security integration with cloud computing.
Feb 14 - http://wivet.googlecode.com
Wivet, a benchmarking project that aims to statistically analyze web link extractors (that is - gauge the quality of a web application security scanner's ability to crawl) recently released version 3 and updated their wiki with new information about scanner results and a future look through their wishlist.
Feb 16 - http://www.owasp.org/index.php/Cincinnati#November_Meeting
The OWASP local chapter in Cincinnati has recently posted a presentation given in November 2008 by Jeremiah Blatz of Foundstone on "Web Application Hacking for Developers".
Feb 18 - http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Smith
The presentaitons and whitepapers for BlackHat DC 2009 were made available, including a fabulous presentation from Colin Ames, Delchi, and Val Smith on "Dissecting Web Attacks".
Feb 15 - http://www.dragoslungu.com/2009/02/15/gartner-magic-quadrant-on-static-application-security-testing-feb-2009/
Feb 20 - http://www.cigital.com/justiceleague/2009/02/19/gartner-and-static-analysis/
Gartner releases a Magic Quadrant on Static Application Security Testing
John Steven at Cigital weighs in with his SAST views
Feb 20 - http://www.securitycatalyst.com/the-balkanization-of-web-application-security/
Bill Pennington theorizes, "most people in the web application security space are a specialist in one particular area, source code review, black box testing, web application firewalls or developer training. This lack of knowledge of the other solutions generally breeds fear and contempt".
Feb 22 - http://appsecnotes.blogspot.com/2009/02/dirbuster-shoots-and-scores.html
Dave Ferguson discusses the OWASP DirBuster tool, developed by James Fisher.
Feb 22 - http://funkatron.com/site/comments/safely-parsing-json-in-javascript/
A discussion about safely parsing JSON in Javascript, which includes Douglas Crocker's prescriptions.
Feb 25 - http://shreeraj.blogspot.com/2009/02/article-on-web-2.html
Shreeraj Shah brings attention to the latest issue of INSECURE magazine, issue 20. The recent magazine includes his article on "Web 2.0 case studies: challenges, approaches and vulnerabilities".
Feb 25 - http://www.owasp.org/index.php/OWASP_AU_Conference_2009
We bring you an update on the happenings at the OWASP AU Conference 2009.

Society of Payment Security Professionals
https://www.paymentsecuritypros.com/en/articles/search.asp?category=Articles
https://www.paymentsecuritypros.com/en/users/login.asp?/appsecurityusergroup/index.asp
SPSP has recently posted information about Education and Training Validity, as well as Certification Validation. Ed Bellis of Orbitz and Trey Ford of WhiteHatSec are heading up the AppSec working group within SPSP, but the information about the group and wiki are currently members only.

Safari and GIFAR
Feb 13 - http://xs-sniper.com/blog/2009/02/13/stealing-more-files-with-safari/
Feb 24 - http://riosec.com/updates-on-gifar-vulnerability
Feb 25 - http://www.cgisecurity.com/2009/02/apple-goes-public-with-security-in-safari-4.html
Billy Rios speaks about the recent Safari security bugs and GIFAR. Robert Auger speaks to the recent security improvements upcoming in Safari version 4.

OWASP Software Assurance Day 2009 Feb 23 - http://www.owasp.org/index.php/OWASP_Software_Assurance_Day_DC_2009
OWASP SnowFROC Feb 12 - http://cleartext.wordpress.com/2009/02/12/march-events/
Two new OWASP events for the month of March!

CanSecWest Vancouver 2009
http://cansecwest.com/speakers.html
An updated speakers list shows that Jeff "rfp" Forristal of Zscaler Research will be presenting on "Network design for effective HTTP traffic filtering" and Chris Weber of Casaba Security will present on "Exploiting Unicode-enabled software". Most security analysts expect to see new Safari, Flash, and/or other exploits in the PWN2OWN Contest!