Difference between revisions of "Switzerland"

From OWASP
Jump to: navigation, search
m (Past Meetings: Centered the icons)
m (Next Meetings: Updated the information about the upcoming meeting.)
(12 intermediate revisions by the same user not shown)
Line 20: Line 20:
 
* Wednesday, December 10th 2014
 
* Wednesday, December 10th 2014
  
<br><!--
+
<br>
 
----
 
----
 
<br>
 
<br>
'''Wednesday, April 9th 2014'''<br>
+
'''Tuesday, June 17th 2014'''<br>
We'd like to invite you to the first of six OWASP Switzerland meetings in 2014. Please make sure to [https://doodle.com/c6sbg6yya498cuwy register] for the event.
+
We'd like to invite you to the third of six OWASP Switzerland meetings in 2014. Please make sure to [http://doodle.com/f4affysew6upxa8c register] for the event.
 
* When:
 
* When:
*:Wednesday, April 9th 2014
+
*:Tuesday, June 17th 2014
 
*:Starting at 18:00
 
*:Starting at 18:00
 
*:Doors at 17:30
 
*:Doors at 17:30
  
 
* What:
 
* What:
*:'''SSL/TLS jungle - bringing light into the cipher forest''' (''by Dobin Rutishauser, Compass Security AG [[Image:person.png|20px|link=https://www.xing.com/profile/Dobin_Rutishauser]]'')
+
*:'''XSS and beyond''' (''René Freingruber, SEC Consult [[Image:person.png|20px|link=https://www.sec-consult.com/]]'')
*:The protocols SSL and TLS are widely used to ensure confidentiality and integrity of data transmitted over insecure networks. As every implementation of crypto algorithms, they come in different versions, and can contain a multitude of errors, faults and configuration options. This talk will shed some light into SSL/TLS basics, and will discuss topics like the secure configuration of the TLS/SSL stack regarding to attacks like BEAST or PRISM, what the impact of Perfect Forward Secrecy is or why nobody should use RC4.
+
*:Cross-Site Scripting (XSS) vulnerabilities are one of the most seen vulnerability categories nowadays. Unfortunately, these vulnerabilities are often underestimated, e.g. because an attacker cannot directly compromise the database or webserver by exploiting them. Instead it’s possible to execute JavaScript code in the context of a user session allowing to steal session cookies, start key-logging, and so on. This talk goes beyond these basic attacks and shows the audience how it’s possible for attackers to completely compromise client systems by exploiting vulnerabilities in browsers. On the basis of real world vulnerabilities, attacks against browsers running on an older operating system (e.g. Windows XP) will be demonstrated. Current operating systems (like Windows 8.1) have implemented lots of mitigation techniques in order to prevent attackers from exploiting such vulnerabilities. During the talk the most important mitigation techniques will be explained. In addition, possible bypasses will be given. At the end of the presentation a real world Firefox exploit, which works reliable against all major Windows versions (including Windows 8.1 and Windows Server 2012), fully bypasses ASLR/DEP (without depending on java6), does not use heapspray and doesn’t crash the browser will be shown to demonstrate that such attacks are still possible and mitigation techniques can be bypassed.
  
 
* Where:
 
* Where:
*:UBS Konferenzgebäude Grünenhof
+
*:Credit Suisse
*:Nüschelerstrasse 9
+
*:Europaallee 1
*:CH-8001 Zürich
+
*:8004 Zürich
*:[http://www.ubs.com/ch/de/conference_centers/gruenenhof/standort.html Arrival]
+
*:[https://www.google.ch/maps/search/Credit+Suisse+Europaallee+1+8004+Zürich Arrival]
  
 
* Who:
 
* Who:
Line 45: Line 45:
 
* Agenda
 
* Agenda
 
*:18:00 – 18:15 | Intro and Update on OWASP by Sven Vetsch, OWASP Switzerland [[Image:person.png|20px|link=User:Disenchant]]
 
*:18:00 – 18:15 | Intro and Update on OWASP by Sven Vetsch, OWASP Switzerland [[Image:person.png|20px|link=User:Disenchant]]
*:18:20 – 19:30 | SSL/TLS jungle - Bringing light into the cipher forest by Dobin Rutishauser, Compass Security AG [[Image:person.png|20px|link=https://www.xing.com/profile/Dobin_Rutishauser]]
+
*:18:20 – 19:30 | XSS and beyond by René Freingruber, SEC Consult [[Image:person.png|20px|link=https://www.sec-consult.com/]]
 
*:20:00 – **:** | Dinner
 
*:20:00 – **:** | Dinner
-->
 
  
 
<!--Fore this year we are planning to serve you with six meetings. The first one will take place in February.<br>
 
<!--Fore this year we are planning to serve you with six meetings. The first one will take place in February.<br>
Line 99: Line 98:
 
| 2013-12-17
 
| 2013-12-17
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2013-December/000262.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2013-December/000262.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 
| <center>[[Image:location.png|20px|link=http://www.credit-suisse.ch/]]</center>
 
| <center>[[Image:location.png|20px|link=http://www.credit-suisse.ch/]]</center>
 
|  
 
|  
Line 123: Line 122:
 
| 2013-04-09
 
| 2013-04-09
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2013-March/000241.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2013-March/000241.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.securesafe.com/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
|  
+
| Tools (not) to use
 
|-
 
|-
 
| 2012-09-19
 
| 2012-09-19
 
|  
 
|  
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.security-zone.info/]]</center>
 
| <center>[[Image:slides.png|20px|link=File:Owasp_top_10_mobile_risks.pdf]]</center>
 
| <center>[[Image:slides.png|20px|link=File:Owasp_top_10_mobile_risks.pdf]]</center>
 
| Security-Zone
 
| Security-Zone
Line 139: Line 138:
 
| 2012-06-12
 
| 2012-06-12
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2012-June/000229.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2012-June/000229.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Tobias_Ospelt]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
|  
+
| Reversing Android Apps
 
|-
 
|-
 
| 2012-02-14
 
| 2012-02-14
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2012-February/000224.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2012-February/000224.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.blackhat.com/html/bh-us-12/speakers/Gianni-Gnesa.html]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| Chapter Meeting
 +
| Analysis of the RSA Security Breach
 +
|-
 +
| 2011-12-13
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-December/000223.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Alexis_FitzGerald]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
|
+
| AppSec - Why is it important
 
|-
 
|-
 
| 2011-12-13
 
| 2011-12-13
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-December/000223.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-December/000223.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Stephan_Berger37]][[Image:person.png|20px|link=https://plus.google.com/106548980928636767176/posts]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
|  
+
| Dangers of Firefox Add-On's
 
|-
 
|-
 
| 2011-10-11
 
| 2011-10-11
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-September/000218.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-September/000218.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Cyrill_Brunschwiler]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.itacs.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
|  
+
| Presentation of the OWASP Top 10 & a hands-on session
 
|-
 
|-
 
| 2011-08-09
 
| 2011-08-09
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-August/000215.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-August/000215.html]]</center>
 +
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| Chapter Meeting
|
+
| Foundation of OWASP Switzerland Association  
| Foundation of OWASP Switzerland Association
+
|
+
 
|-
 
|-
 
| 2011-06-14
 
| 2011-06-14
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-June/000208.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-June/000208.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Pascal_Buchbinder]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Pascal_Buchbinder]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
| <center>[[Image:slides.png|20px|link=File:Owasl_lcm_20110614_mod_sslcrl.pdf]]</center>
 
| <center>[[Image:slides.png|20px|link=File:Owasl_lcm_20110614_mod_sslcrl.pdf]]</center>
 
| Chapter Meeting
 
| Chapter Meeting
Line 188: Line 195:
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-June/000208.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-June/000208.html]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
| <center>[[Image:slides.png|20px|link=File:OWASP_Browser_Security.pdf]]</center>
 
| <center>[[Image:slides.png|20px|link=File:OWASP_Browser_Security.pdf]]</center>
 
| Chapter Meeting
 
| Chapter Meeting
Line 196: Line 203:
 
|  
 
|  
 
| <center>[[Image:person.png|20px|link=User:Afontes]]</center>
 
| <center>[[Image:person.png|20px|link=User:Afontes]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.swisscyberstorm.com/]]</center>
 
| <center>[[Image:slides.png|20px|link=https://www.owasp.org/index.php/File:SwissCyberStorm3-Do_you_know_OWASP.pdf]]</center>
 
| <center>[[Image:slides.png|20px|link=https://www.owasp.org/index.php/File:SwissCyberStorm3-Do_you_know_OWASP.pdf]]</center>
 
| Swiss Cyber Storm III
 
| Swiss Cyber Storm III
|  
+
| Do you know OWASP?
 
|-
 
|-
 
| 2011-04-12
 
| 2011-04-12
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-April/000204.htmll]]</center>
+
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2011-April/000204.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Alexandre_Herzog]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Alexandre_Herzog]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
| <center>[[Image:slides.png|20px|link=File:20110412-aspnet_viewstate_security-alexandre.pdf]]</center>
 
| <center>[[Image:slides.png|20px|link=File:20110412-aspnet_viewstate_security-alexandre.pdf]]</center>
 
| Chapter Meeting
 
| Chapter Meeting
Line 212: Line 219:
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2010-February/000152.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2010-February/000152.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Tobias_Christen]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Tobias_Christen]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
Line 220: Line 227:
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2010-February/000152.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2010-February/000152.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Michael_Tschannen]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Michael_Tschannen]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.rheinfelder.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
Line 227: Line 234:
 
| 2009-06-25
 
| 2009-06-25
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2009-June/000144.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2009-June/000144.html]]</center>
 +
| <center>[[Image:person.png|20px|Jerry Hoff]][[Image:person.png|20px|Jason Li]]</center>
 +
| <center>[[Image:location.png|20px|link=https://www.avantec.ch/]]</center>
 
|  
 
|  
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| Chapter Meeting
 +
| Benefits of a security API such as ESAPI
 +
|-
 +
| 2009-06-25
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2009-June/000144.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Bruno_Blumenthal]]</center>
 +
| <center>[[Image:location.png|20px|link=https://www.avantec.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
 +
| Advanced SQL injection exploitation to operating system full control
 +
|-
 +
| 2009-04-07
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2009-March/000140.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Tobias_Christen]]</center>
 +
| <center>[[Image:location.png|20px|link=https://www.avantec.ch/]]</center>
 
|  
 
|  
 +
| Chapter Meeting
 +
| Open security architecture (www.opensecurityarchitecture.org)
 
|-
 
|-
 
| 2009-04-07
 
| 2009-04-07
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2009-March/000140.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2009-March/000140.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Cyrill_Brunschwiler]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.avantec.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
 +
| XSRF and JSON hijacking & a hands-on session
 +
|-
 +
| 2008-09-08
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2008-August/000132.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Pascal_Buchbinder]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.swissre.com/]]</center>
 
|  
 
|  
 +
| Chapter Meeting
 +
| Quality of services for web applications (Hands-On Workshop)
 
|-
 
|-
 
| 2008-09-08
 
| 2008-09-08
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2008-August/000132.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2008-August/000132.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Cyrill_Brunschwiler]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.swissre.com/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
 +
| XML Security (Hands-On Workshop)
 +
|-
 +
| 2008-09-08
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2008-August/000132.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Alessandro_Moretti]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.swissre.com/]]</center>
 
|  
 
|  
 +
| Chapter Meeting
 +
| ISC2/Application security
 
|-
 
|-
 
| 2008-04-01
 
| 2008-04-01
|  
+
| <center>[[Image:info.png|20px|link=http://lists.owasp.org/pipermail/owasp-switzerland/2008-March/000114.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Christian_Folini]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Christian_Folini]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.ethz.ch/]]</center>
 
|  
 
|  
 
| Global OWASP Week
 
| Global OWASP Week
Line 258: Line 297:
 
|-
 
|-
 
| 2008-04-01
 
| 2008-04-01
|  
+
| <center>[[Image:info.png|20px|link=http://lists.owasp.org/pipermail/owasp-switzerland/2008-March/000114.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Alessandro_Moretti]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Alessandro_Moretti]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.ethz.ch/]]</center>
 
|  
 
|  
 
| Global OWASP Week
 
| Global OWASP Week
Line 266: Line 305:
 
|-
 
|-
 
| 2008-04-01
 
| 2008-04-01
|  
+
| <center>[[Image:info.png|20px|link=http://lists.owasp.org/pipermail/owasp-switzerland/2008-March/000114.html]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.ethz.ch/]]</center>
 
|  
 
|  
 
| Global OWASP Week
 
| Global OWASP Week
Line 275: Line 314:
 
| 2007-12-11
 
| 2007-12-11
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-November/000106.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-November/000106.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Thomas_Bader]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.zurich.com/]]</center>
 
|  
 
|  
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| Chapter Meeting
 +
| Certified Secure Web
 +
|-
 +
| 2007-12-11
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-November/000106.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/Tobias_Christen]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.zurich.com/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
 +
| Secure Development Life Cycle
 +
|-
 +
| 2007-12-11
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-November/000106.html]]</center>
 +
| <center>[[Image:person.png|20px|Daniel Hulliger]]</center>
 +
| <center>[[Image:location.png|20px|link=http://www.zurich.com/]]</center>
 
|  
 
|  
 +
| Chapter Meeting
 +
| Securing my Assets (Presentation & Demo)
 
|-
 
|-
 
| 2007-09-20
 
| 2007-09-20
 
| <center>[[Image:info.png|20px|link=http://www.disenchant.ch/blog/owasp-switzerland-goes-public/80]]</center>
 
| <center>[[Image:info.png|20px|link=http://www.disenchant.ch/blog/owasp-switzerland-goes-public/80]]</center>
|  
+
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.security-zone.info/]]</center>
 
|  
 
|  
 
| Security-Zone
 
| Security-Zone
|  
+
| OWASP Testing Guide
 
|-
 
|-
 
| 2007-09-19
 
| 2007-09-19
 
| <center>[[Image:info.png|20px|link=http://www.disenchant.ch/blog/owasp-switzerland-goes-public/80]]</center>
 
| <center>[[Image:info.png|20px|link=http://www.disenchant.ch/blog/owasp-switzerland-goes-public/80]]</center>
|  
+
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=http://www.security-zone.info/]]</center>
 
|  
 
|  
 
| Security-Zone
 
| Security-Zone
 +
| OWASP Top 10
 +
|-
 +
| 2007-07-24
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-July/000095.html]]</center>
 +
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 +
| <center>[[Image:location.png|20px|link=https://www.zurich.ch/]]</center>
 
|  
 
|  
 +
| Chapter Meeting
 +
| OWASP - An Overview
 
|-
 
|-
 
| 2007-07-24
 
| 2007-07-24
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-July/000095.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-July/000095.html]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Pierre_Parrend]]</center>
 
| <center>[[Image:person.png|20px|link=https://www.xing.com/profiles/Pierre_Parrend]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.zurich.ch/]]</center>
 
| <center>[[Image:slides.png|20px|link=Mobile_Java_Security]]</center>
 
| <center>[[Image:slides.png|20px|link=Mobile_Java_Security]]</center>
 
| Chapter Meeting
 
| Chapter Meeting
 
| Dependability for Java Mobile Code
 
| Dependability for Java Mobile Code
 +
|-
 +
| 2007-07-24
 +
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-July/000095.html]]</center>
 +
| <center>[[Image:person.png|20px|link=https://www.xing.com/profile/HansPeter_Waldegger]][[Image:person.png|20px|link=https://www.xing.com/profiles/Pascal_Buchbinder]]</center>
 +
| <center>[[Image:location.png|20px|link=https://www.zurich.ch/]]</center>
 +
|
 +
| Chapter Meeting
 +
| OWASP Top 10 (Demo)
 
|-
 
|-
 
| 2007-04-26
 
| 2007-04-26
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-April/000086.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-April/000086.html]]</center>
|  
+
| <center>[[Image:person.png|20px|link=http://www.linkedin.com/in/bchess]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.zurich.ch/]]</center>
 
|  
 
|  
 
| Chapter Meeting
 
| Chapter Meeting
|  
+
| Risk metrics
 
|-
 
|-
 
| 2007-02-12
 
| 2007-02-12
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-February/000079.html]]</center>
 
| <center>[[Image:info.png|20px|link=https://lists.owasp.org/pipermail/owasp-switzerland/2007-February/000079.html]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
+
| <center>[[Image:location.png|20px|link=https://www.zurich.ch/]]</center>
 
| <center>[[Image:slides.png|20px|link=File:20070212-xss_worms-disenchant.pdf]]</center>
 
| <center>[[Image:slides.png|20px|link=File:20070212-xss_worms-disenchant.pdf]]</center>
 
| Chapter Meeting
 
| Chapter Meeting
Line 323: Line 394:
 
| 2006-11-11
 
| 2006-11-11
 
|  
 
|  
 +
| <center>[[Image:person.png|20px|link=User:Disenchant]]</center>
 
|  
 
|  
| <center>[[Image:location.png|20px|link=http://www.owasp.ch]]</center>
 
 
|  
 
|  
 +
| Chapter Meeting
 
| OWASP Switzerland Chapter Kick-Off Meeting
 
| OWASP Switzerland Chapter Kick-Off Meeting
|
 
 
|}
 
|}
  

Revision as of 08:42, 4 June 2014


[edit]

OWASP Switzerland Chapter Logo

Welcome to the Home Page of the OWASP Switzerland Chapter.


If you're living in the French speaking part of Switzerland, please also visit the OWASP Geneva chapter for more information.

Please find below the planned dates for the upcoming OWASP Switzerland Meetings:

  • Tuesday, June 17th 2014
  • Wednesday, August 20th 2014
  • Tuesday, October 21th 2014
  • Wednesday, December 10th 2014




Tuesday, June 17th 2014
We'd like to invite you to the third of six OWASP Switzerland meetings in 2014. Please make sure to register for the event.

  • When:
    Tuesday, June 17th 2014
    Starting at 18:00
    Doors at 17:30
  • What:
    XSS and beyond (René Freingruber, SEC Consult Person.png)
    Cross-Site Scripting (XSS) vulnerabilities are one of the most seen vulnerability categories nowadays. Unfortunately, these vulnerabilities are often underestimated, e.g. because an attacker cannot directly compromise the database or webserver by exploiting them. Instead it’s possible to execute JavaScript code in the context of a user session allowing to steal session cookies, start key-logging, and so on. This talk goes beyond these basic attacks and shows the audience how it’s possible for attackers to completely compromise client systems by exploiting vulnerabilities in browsers. On the basis of real world vulnerabilities, attacks against browsers running on an older operating system (e.g. Windows XP) will be demonstrated. Current operating systems (like Windows 8.1) have implemented lots of mitigation techniques in order to prevent attackers from exploiting such vulnerabilities. During the talk the most important mitigation techniques will be explained. In addition, possible bypasses will be given. At the end of the presentation a real world Firefox exploit, which works reliable against all major Windows versions (including Windows 8.1 and Windows Server 2012), fully bypasses ASLR/DEP (without depending on java6), does not use heapspray and doesn’t crash the browser will be shown to demonstrate that such attacks are still possible and mitigation techniques can be bypassed.
  • Where:
    Credit Suisse
    Europaallee 1
    8004 Zürich
    Arrival
  • Who:
    As usual, all of our meetings are open to everyone and free of charge.
  • Agenda
    18:00 – 18:15 | Intro and Update on OWASP by Sven Vetsch, OWASP Switzerland Person.png
    18:20 – 19:30 | XSS and beyond by René Freingruber, SEC Consult Person.png
    20:00 – **:** | Dinner


Date Info Speaker Host Slides Event Topic
2014-04-09
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting SSL/TLS jungle - bringing light into the cipher forest
2014-02-19
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting S-SDLC – Ready for Clouds?
2013-12-17
Info.png
Person.png
Location.png
Chapter Meeting Annual Review & Outlook
2013-10-22
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting Advances in secure (ASP).NET development – Break the hacker's spirit
2013-10-22
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting Node.js Security
2013-04-09
Info.png
Person.png
Location.png
Chapter Meeting Tools (not) to use
2012-09-19
Person.png
Location.png
Slides.png
Security-Zone OWASP Top 10 Mobile Risks
2012-06-12
Info.png
Person.png
Location.png
Chapter Meeting Reversing Android Apps
2012-02-14
Info.png
Person.png
Location.png
Chapter Meeting Analysis of the RSA Security Breach
2011-12-13
Info.png
Person.png
Location.png
Chapter Meeting AppSec - Why is it important
2011-12-13
Info.png
Person.pngPerson.png
Location.png
Chapter Meeting Dangers of Firefox Add-On's
2011-10-11
Info.png
Person.png
Location.png
Chapter Meeting Presentation of the OWASP Top 10 & a hands-on session
2011-08-09
Info.png
Person.png
Location.png
Chapter Meeting Foundation of OWASP Switzerland Association
2011-06-14
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting Automatic CRL updates for the Apache Web server
2011-06-14
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting New Standards and upcoming Technologies in Browser Security (Slides by Tobias Gondrom)
2011-05-12
Person.png
Location.png
Slides.png
Swiss Cyber Storm III Do you know OWASP?
2011-04-12
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting ASP.NET & ViewState Security
2010-04-12
Info.png
Person.png
Location.png
Chapter Meeting Usability vs. Security
2010-04-12
Info.png
Person.png
Location.png
Chapter Meeting 2-factor authentication for mobile devices: a secure and practical approach
2009-06-25
Info.png
Jerry HoffJason Li
Location.png
Chapter Meeting Benefits of a security API such as ESAPI
2009-06-25
Info.png
Person.png
Location.png
Chapter Meeting Advanced SQL injection exploitation to operating system full control
2009-04-07
Info.png
Person.png
Location.png
Chapter Meeting Open security architecture (www.opensecurityarchitecture.org)
2009-04-07
Info.png
Person.png
Location.png
Chapter Meeting XSRF and JSON hijacking & a hands-on session
2008-09-08
Info.png
Person.png
Location.png
Chapter Meeting Quality of services for web applications (Hands-On Workshop)
2008-09-08
Info.png
Person.png
Location.png
Chapter Meeting XML Security (Hands-On Workshop)
2008-09-08
Info.png
Person.png
Location.png
Chapter Meeting ISC2/Application security
2008-04-01
Info.png
Person.png
Location.png
Global OWASP Week Taking Apache access logs to the next level
2008-04-01
Info.png
Person.png
Location.png
Global OWASP Week Implementing an Application Security Lifecycle programme
2008-04-01
Info.png
Person.png
Location.png
Global OWASP Week WebAppSec the Big Picture
2007-12-11
Info.png
Person.png
Location.png
Chapter Meeting Certified Secure Web
2007-12-11
Info.png
Person.png
Location.png
Chapter Meeting Secure Development Life Cycle
2007-12-11
Info.png
Daniel Hulliger
Location.png
Chapter Meeting Securing my Assets (Presentation & Demo)
2007-09-20
Info.png
Person.png
Location.png
Security-Zone OWASP Testing Guide
2007-09-19
Info.png
Person.png
Location.png
Security-Zone OWASP Top 10
2007-07-24
Info.png
Person.png
Location.png
Chapter Meeting OWASP - An Overview
2007-07-24
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting Dependability for Java Mobile Code
2007-07-24
Info.png
Person.pngPerson.png
Location.png
Chapter Meeting OWASP Top 10 (Demo)
2007-04-26
Info.png
Person.png
Location.png
Chapter Meeting Risk metrics
2007-02-12
Info.png
Person.png
Location.png
Slides.png
Chapter Meeting XSS-Worms
2006-11-11
Person.png
Chapter Meeting OWASP Switzerland Chapter Kick-Off Meeting


OWASP Chapter meetings are free and open. Our chapter's meetings are informal and encourage open discussion of all aspects of application security. Anyone in our area interested in application security is welcome to attend. We encourage attendees to give short presentations about specific topics.


Our main topics are:

  • Security testing
  • Secure development
  • Hacking
  • Secure Architectures


If you would like to give a presentation (make sure that you have read and understood the speaker agreement), or have any questions about the OWASP Switzerland Chapter, send an email to Sven Vetsch.

Help us to make application security visible and become a supporter of the OWASP or our Chapter in Switzerland. All information about becoming a member/sponsor can be found here.

If your company is interested in supporting us directly, please contact Sven Vetsch to talk about the following sponsoring possibilities.

  • Chapter Supporter
  • Single Meeting Supporter
  • Facility Sponsor
  • Organization Supporters (allocating 40% of your annual donation to our Chapter)

Here you can find material related to the OWASP Switzerland Chapter.

OWASP Switzerland bylaws (in German)
Download bylaws

OWASP Switzerland Update Presentation (December 13th 2011)
Download Presentation

funds to OWASP earmarked for Switzerland.

Join the list.png Follow-us-on-twitter.png Facebook-icon.png