OWASP NYC APPSEC 2008 CONFERENCE
Video Content Viewing and Downloads

Bookmark and Add

Social Bookmarks

The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to develop, acquire, and maintain applications that can be trusted on the internet. The mission of the OWASP Foundation is to make application security "visible," so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work. OWASP is like "public radio" so support our efforts join today as a corporate or individual member learn more CLICK HERE

SEE BELOW FOR VIDEO AND SLIDES - CLICK HERE FOR PHOTOS
Join the OWASP Linked'In Group

Also visit www.OWASP.tv - Your Source for AppSec and InfoSec Videos

Video content produced, processed and posted by www.MediaArchives.com


Day 1 – Sept 24th, 2008

Track 1: BALLROOM Track 2: SKYLINE Track 3: TIMESQUARE
07:30-08:50 Doors Open for Attendee/Speaker Registration
09:00-09:45
Play Video in a New Window
View Dave Wichers's SLIDES Here

OWASP Version 3.0 - Who We Are, How We Got Here and Where We Are Going?
OWASP Foundation: Jeff Williams, Dinis Cruz, Dave Wichers, Tom Brennan, Sebastien Deleersnyder, Paulo Coimbra, Kate Hartmann, Alison Shrader & all local chapter leaders

10:00-10:45


Play Video in a New Window
Download Presentation SLIDES Here

Analysis of the Web Hacking Incidents Database (WHID)
Ofer Shezaf


Play Video in a New Window
Download Presentation SLIDES Here

Web Application Security Road Map
Joe White


Play Video in a New Window
Download Presentation SLIDES Here

DHS Software Assurance Initiatives
Stan Wisseman & Joe Jarzombek

11:00-11:45

Play Video in a New Window
Download Presentation SLIDES Here

HTTP Bot Research
Steven Adair - ShadowServer Foundation


Play Video in a New Window
Download Presentation SLIDES Here

The OWASP "Google Hacking" Project
Christian Heinrich


Play Video in a New Window
Download Presentation SLIDES Here

MalSpam Research
Garth Bruen

12:00-13:00 Capture the Flag Sign-Up
LUNCH - Provided by event sponsors @ TechExpo
12:00-12:45

Play Video in a New Window
Download Presentation SLIDES Here

Get Rich or Die Trying: Making Money on The Web - The Black Hat Way
Trey Ford, Tom Brennan, Jeremiah Grossman


Play Video in a New Window
Download Presentation SLIDES Here

Framework-Level Threat Analysis: Adding Science to the Art of Source Code Review
Rohit Sethi & Sahba Kazerooni


Play Video in a New Window
Download Presentation SLIDES Here

Automated Web-based Malware Behavioral Analysis
Tyler Hudak

13:00-13:45

Play Video in a New Window
Download Presentation SLIDES Here

New Zero-Day Browser Exploits: Clickjacking - Yea, This is Bad...
Jeremiah Grossman & Robert "RSnake" Hansen


Play Video in a New Window
Download Presentation SLIDES Here

Web Intrusion Detection with ModSecurity
Ivan Ristic


Play Video in a New Window
Download Presentation SLIDES Here

Using Layer 8 and OWASP to Secure Web Applications
David Stern & Roman Garber

14:00-14:45

Play Video in a New Window
Download Presentation SLIDES Here

Application Security Industry Outlook Panel
Jim Routh CISO DTCC; Sunil Seshadri CISO NYSE-Euronet; Joe Bernik SVP, RBS Americas; Jennifer Bayuk Infosec Consultant; Philip Venables CISO, Goldman Sachs; Carlos Recalde SVP Lehman Brothers; with Mahi Dontamsetti as Moderator


Play Video in a New Window
Download Presentation SLIDES Here

Security Assessing Java RMI
Adam Boulton


Play Video in a New Window
Download Presentation SLIDES Here

JBroFuzz 0.1 - 1.1: Building a Java Fuzzer for the Web
Yiannis Pavlosoglou

15:00-15:45

Play Video in a New Window
Download Presentation SLIDES Here

OWASP Testing Guide - Offensive Assessing Financial Applications
Daniel Cuthbert


Play Video in a New Window
Download Presentation SLIDES Here

Flash Parameter Injection (FPI)
Ayal Yogev & Adi Sharabani


Play Video in a New Window

Download Presentation SLIDES Here

w3af - A Framework to Own the Web
Andres Riancho

16:00-16:45

Play Video in a New Window
Download Presentation SLIDES Here

OWASP Enterprise Security API (ESAPI) Project
Jeff Williams


Play Video in a New Window
Download Presentation SLIDES Here

Cross-Site Scripting Filter Evasion
Alexios Fakos


Play Video in a New Window
Download Presentation SLIDES Here

Multidisciplinary Bank Attacks
Gunter Ollmann

17:00-17:45

Play Video in a New Window
Download Presentation SLIDES Here

An Open Discussion on Application Security
Joe Bernik and Steve Antoniewicz


Play Video in a New Window
Download Presentation SLIDES Here

Mastering PCI Section 6.6
Taylor McKinley and Jacob West


Play Video in a New Window
Download Presentation SLIDES Here

Exploiting Application Testing Tool Deficiencies via "Out of Band" Injection
Vijay Akasapu and Marshall Heilman

18:00-18:45

Play Video in a New Window
Download Presentation SLIDES Here

Spearphishing and the OWASP Live CD
Joshua Perrymon


Play Video in a New Window
Download Presentation SLIDES Here

Phundamental Security - Coding Secure w/PHP
Hans Zaunere


Play Video in a New Window
Download Presentation SLIDES Here

Payment Card Data Security and the New Enterprise Java
Dr. B. V. Kumar & Mr. Abhay Bhargav

20:00-23:00+ OWASP Event Party/Reception
Food, Drinks w/ New & Old Friends - break out the laptop and play capture the flag for fun and prizes.

Day 2 – Sept 25th, 2008

08:00-10:00 BREAKFAST - Provided by event sponsors @ TechExpo
08:00-08:45

Play Video in a New Window
Download Presentation SLIDES Here

Software Development and Management: The Last Security Frontier
W. Hord Tipton, CISSP-ISSEP, CAP, CISA, CNSS and former Chief Information Officer for the U.S. Department of the Interior Executive Director and member of the Board of Directors, (ISC)2


Play Video in a New Window
Download Presentation SLIDES Here

Best Practices Guide: Web Application Firewalls
Alexander Meisel


Play Video in a New Window
Download Presentation SLIDES Here

The Good The Bad and The Ugly - Pen Testing vs. Source Code Analysis
Thomas Ryan

09:00-09:45

Play Video in a New Window
Download Presentation SLIDES Here

OWASP Web Services Top Ten
Gunnar Peterson


Play Video in a New Window
Download Presentation SLIDES Here

Red and Tiger Team Application Security Projects
Chris Nickerson


Play Video in a New Window
Download Presentation SLIDES Here

OpenSource Tools
Prof. Li-Chiou Chen & Chienitng Lin, Pace Univ

10:00-10:45

Play Video in a New Window
Download Presentation SLIDES Here

Building a Tool for Security Consultants: A Customized Source Code Scanner
Dinis Cruz


Play Video in a New Window
Download Presentation SLIDES Here

"Help Wanted" - 7 Things You Need to Know AppSec and InfoSec Employment
Lee Kushner


Play Video in a New Window
Download Presentation SLIDES Here

Industry Analyst with Forrester Research
Chenxi Wang

11:00-11:45

Play Video in a New Window
Download Presentation SLIDES Here

CLASP (Comprehensive, Lightweight Application Security Process)
Pravir Chandra


Play Video in a New Window
Download Presentation SLIDES Here

Security in Agile Development
Dave Wichers


Play Video in a New Window
Download Presentation SLIDES Here

Secure Software Impact
Jack Danahy

12:00-12:45

Play Video in a New Window
Download Presentation SLIDES Here

Next Generation Cross Site Scripting Worms
Arshan Dabirsiaghi


Play Video in a New Window
Download Presentation SLIDES Here

Security of Software-as-a-Service (SaaS)
James Landis


Play Video in a New Window
Download Presentation SLIDES Here

Open Reverse Benchmarking Project
Marce Luck & (Tom Stracener)

12:00-13:00 Capture the Flag Status
LUNCH - Provided @ TechExpo
13:00-13:45

Play Video in a New Window
Download Presentation SLIDES Here

NIST SAMATE Static Analysis Tool Exposition (SATE)
Vadim Okun


Play Video in a New Window
Download Presentation SLIDES Here

Lotus Notes / Domino Web Application Security
Jian Hui Wang


Play Video in a New Window
Download Presentation SLIDES Here

Shootout @ Blackbox Corral
Larry Suto

14:00-14:45

Play Video in a New Window
Download Presentation SLIDES Here

Practical Advanced Threat Modeling
John Steven


Play Video in a New Window
Download Presentation SLIDES Here

The Owasp Orizon Project: Towards Version 1.0
Paolo Perego


Play Video in a New Window
Download Presentation SLIDES Here

Building Usable Security

Zed Abbadi

15:00-15:45

Play Video in a New Window
Download Presentation SLIDES Here

Off-Shoring Application Development? Security is Still Your Problem
Rohyt Belani


Play Video in a New Window
Download Presentation SLIDES Here

OWASP EU Summit Portugal
Dinis Cruz


Play Video in a New Window
Download Presentation SLIDES Here

A Security Architecture Case Study
Johan Peeters

16:00-16:45

Play Video in a New Window
Download Presentation SLIDES Here

Vulnerabilities in Application Interpreters and Runtimes
Erik Cabetas


Play Video in a New Window
Download Presentation SLIDES Here

Cryptography for Penetration Testers
Chris Eng


Play Video in a New Window
Download Presentation SLIDES Here

Memory Corruption and Buffer Overflows
Dave Aitel

17:00-17:45


Play Video in a New Window

Event Wrap-Up / Speaker & CTF Awards and Sponsor Raffles


Video content produced, processed and posted by www.MediaArchives.com

The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to develop, purchase, and maintain applications that can be trusted on the internet. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. OWASP advocates approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. More information on the Open Web Application Security Project can be found at www.owasp.org


OWASP Conference San Jose – Nov 14, 2007

Track 1: Nov 14, 2007 Track 2: Nov 14, 2007
07:30-08:50 Doors Open for Attendee/Speaker Registration
09:00-09:10


Play Video in a New Window
View Dave Wichers's SLIDES Here

Welcome to OWASP & WASC AppSec 2007 Conference
Dave Wichers, OWASP Conferences Chair and COO Aspect Security (ppt)



Play Video in a New Window

Keynote: eBay Application Security Program
Dave Cullinane, CISO - eBay and Michael Barrett, CISO - PayPal [Softcopy not available]



Play Video in a New Window
View SLIDES Here

An Introduction to WASC and Its Projects (pdf)
Jeremiah Grossman, CTO, WhiteHat Security



Play Video in a New Window
View SLIDES Here (66 Megs)

Using OWASP for Application Security (VERY LARGE - 66MB - ppt)
Jeff Williams, OWASP Chair and CEO - Aspect Security

9:10-10:00
10:00-10:30
11:20-12:20

Play Video in a New Window
Download Presentation SLIDES Here

For My Next Trick... Hacking Web 2.0 (ppt)
Petko D. Petkov (AKA PDP Architect), Senior Security Researcher. Full version presented at OWASP Day Sept 2007 in Brussels (ppt)

"Video Unavailable"

Backdoors and other Developer Introduced 'Features' (ppt)
Chris Wysopal, CTO Veracode

13:45-14:30

Play Video in a New Window
Download Presentation SLIDES Here

CSRF: Danger, Detection, and Defenses – Introducing two new OWASP CSRF Tools (ppt)
Eric Sheridan, Application Security Consultant, Aspect Security and OWASP CSRF Guard Project Lead


Play Video in a New Window
Download Presentation SLIDES Here

WASC Distributed Open Proxy Honeypot Project (ppt)
Ryan Barnett, WASC Open Proxy Honeypot Project Lead, Breach Security

14:30-15:10

Play Video in a New Window
Download Presentation SLIDES Here

Defeating Web 2.0 Attacks without Recoding Applications (ppt)
Amichai Shulman, CTO, Imperva


Play Video in a New Window
Download Presentation SLIDES Here

Dangers of Third Party Content (ppt)
Tom Stripling, Senior Security Consultant - Security PS

15:30-16:40

Play Video in a New Window

OWASP Projects Overview [No PPT]
Dinis Cruz, Chief OWASP Evangelist


Play Video in a New Window
Download Presentation SLIDES Here

Web Browser (In)-Security - "Past, Present, and Future" (ppt)
Robert "RSnake" Hansen, CEO SecTheory

17:00-18:00

Play Video in a New Window

Panel: “Building an Effective Application Security Assurance Program”
Moderator: Brian Bertacini, Sr. Manager, AppSec Consulting
Panelists: Jeff Williams - CEO Aspect Security
Andy Steingruebl - Principal Security Engineer PayPal
Gary Terrell, Adobe Systems
Scott Stender, iSEC Partners, Neil Daswani, Google


Play Video in a New Window
Download Presentation SLIDES Here

OWASP Leader Meeting (see meeting agenda here)
Organized by Dinis Cruz

CLICK HERE for the Full Agenda from the San Jose OWASP 2007 Conference

OWASP Conference San Jose – Nov 14, 2007

Track 1: Nov 14, 2007 Track 2: Nov 14, 2007
Doors Open for Attendee/Speaker Registration

10:50-11:30

Play Video in a New Window
Download Presentation SLIDES Here

Start Rolling with Rails Security (ppt)
Corey Benninger, Principal Consultant, Intrepidus Group, Inc.

11:30-12:30

Play Video in a New Window
Download Presentation SLIDES Here

Securing Java Server Faces Against the OWASP Top 10 (ppt)
David Chandler, Web Architect, Digital Insight

13:45-14:30

Play Video in a New Window
Download Presentation SLIDES Here

.Net Web Services Hacking - Scan, Attacks and Defense (ppt)
Sheeraj Shah, Blueinfy

14:30-15:20

Play Video in a New Window

Website Vulnerability Statistics
Arian Evans (Director of Operations, WhiteHat Security)

15:40-16:30


Play Video in a New Window

Session Management Security and Assessment Techniques
Tom Stracener, Sr. Security Analyst, Cenzic

Metadata includes: www.OWASP.org - The Open Web Application Security Project Foundation - www.OWASP.tv - Your Source for AppSec and InfoSec Video - Community, Organizations, Tools, Web, Internet, Forums, Chapters, Black Hat, White Hat, Blackbox, Whitebox, Hack, Hacking, Security, Invasion, NIST, SAMATE, PCI, FPI, WHID, SaaS, Spam, Bots, Malware, Analysis, Zero-Day, Exploits, Java, Fuzzing, Fuzzer, Flash, Parameter, SQL Injection, Spearphishing, Firewalls, Pen Testing, Source Code, Memory, Penetration Testing, Vulns, Vulnerabilities, Open Source, Cross-Site, Scripting, Threat Modeling, Cryptography, Crypto, Agile, DHS, Software, Google, Layer, Financial, Coding, Secure, Card Data, Enterprise, Firewall, Orizon, Off-Shoring, Outsourcing, Interepreters, Runtimes