OWASP NYC APPSEC 2008 CONFERENCE
Video Content Viewing and Downloads
The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to develop, acquire, and maintain applications that can be trusted on the internet. The mission of the OWASP Foundation is to make application security "visible," so that people and organizations can make informed decisions about application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work. OWASP is like "public radio" so support our efforts join today as a corporate or individual member learn more CLICK HERE
SEE BELOW FOR VIDEO AND SLIDES - CLICK HERE FOR PHOTOS
Join the OWASP Linked'In Group
Also visit www.OWASP.tv - Your Source for AppSec and InfoSec Videos
Video content produced, processed and posted by www.MediaArchives.com
Day 1 Sept 24th, 2008 |
|||||||||
|---|---|---|---|---|---|---|---|---|---|
| Track 1: BALLROOM | Track 2: SKYLINE | Track 3: TIMESQUARE | |||||||
| 07:30-08:50 | Doors Open for Attendee/Speaker Registration | ||||||||
| 09:00-09:45 | Play Video in a New Window View Dave Wichers's SLIDES Here OWASP Version 3.0 - Who We Are, How We Got Here and Where We Are Going? |
||||||||
| 10:00-10:45 |
Analysis of the Web Hacking Incidents Database (WHID) |
Web Application Security Road Map |
DHS Software Assurance Initiatives |
||||||
| 11:00-11:45 |
Play Video in a New Window Download Presentation SLIDES Here HTTP Bot Research |
Play Video in a New Window Download Presentation SLIDES Here The OWASP "Google Hacking" Project |
Play Video in a New Window Download Presentation SLIDES Here MalSpam Research |
||||||
| 12:00-13:00 | Capture the Flag Sign-Up
LUNCH - Provided by event sponsors @ TechExpo |
||||||||
| 12:00-12:45 |
Play Video in a New Window Download Presentation SLIDES Here Get Rich or Die Trying: Making Money on The Web - The Black Hat Way |
Play Video in a New Window Download Presentation SLIDES Here Framework-Level Threat Analysis: Adding Science to the Art of Source Code Review |
Play Video in a New Window Download Presentation SLIDES Here Automated Web-based Malware Behavioral Analysis |
||||||
| 13:00-13:45 |
Play Video in a New Window Download Presentation SLIDES Here New Zero-Day Browser Exploits: Clickjacking - Yea, This is Bad... |
Play Video in a New Window Download Presentation SLIDES Here Web Intrusion Detection with ModSecurity |
Play Video in a New Window Download Presentation SLIDES Here Using Layer 8 and OWASP to Secure Web Applications |
||||||
| 14:00-14:45 |
Play Video in a New Window Download Presentation SLIDES Here Application Security Industry Outlook Panel |
Play Video in a New Window Download Presentation SLIDES Here Security Assessing Java RMI |
Play Video in a New Window Download Presentation SLIDES Here JBroFuzz 0.1 - 1.1: Building a Java Fuzzer for the Web |
||||||
| 15:00-15:45 |
Play Video in a New Window Download Presentation SLIDES Here OWASP Testing Guide - Offensive Assessing Financial Applications |
Play Video in a New Window Download Presentation SLIDES Here Flash Parameter Injection (FPI) |
Play Video in a New Window
Download Presentation SLIDES Here w3af - A Framework to Own the Web |
||||||
| 16:00-16:45 |
Play Video in a New Window Download Presentation SLIDES Here OWASP Enterprise Security API (ESAPI) Project |
Play Video in a New Window Download Presentation SLIDES Here Cross-Site Scripting Filter Evasion |
Multidisciplinary Bank Attacks |
||||||
| 17:00-17:45 |
Play Video in a New Window Download Presentation SLIDES Here An Open Discussion on Application Security |
Play Video in a New Window Download Presentation SLIDES Here Mastering PCI Section 6.6 |
Play Video in a New Window Download Presentation SLIDES Here Exploiting Application Testing Tool Deficiencies via "Out of Band" Injection |
||||||
| 18:00-18:45 |
Play Video in a New Window Download Presentation SLIDES Here Spearphishing and the OWASP Live CD |
Play Video in a New Window Download Presentation SLIDES Here Phundamental Security - Coding Secure w/PHP |
Play Video in a New Window Download Presentation SLIDES Here Payment Card Data Security and the New Enterprise Java |
||||||
| 20:00-23:00+ | OWASP Event Party/Reception Food, Drinks w/ New & Old Friends - break out the laptop and play capture the flag for fun and prizes. |
||||||||
Day 2 Sept 25th, 2008 |
|||||||||
| 08:00-10:00 | BREAKFAST - Provided by event sponsors @ TechExpo | ||||||||
| 08:00-08:45 |
Play Video in a New Window Download Presentation SLIDES Here Software Development and Management: The Last Security Frontier |
Play Video in a New Window Download Presentation SLIDES Here Best Practices Guide: Web Application Firewalls |
Play Video in a New Window Download Presentation SLIDES Here The Good The Bad and The Ugly - Pen Testing vs. Source Code Analysis |
||||||
| 09:00-09:45 |
Play Video in a New Window Download Presentation SLIDES Here OWASP Web Services Top Ten |
Play Video in a New Window Download Presentation SLIDES Here Red and Tiger Team Application Security Projects |
Play Video in a New Window Download Presentation SLIDES Here OpenSource Tools |
||||||
| 10:00-10:45 |
Play Video in a New Window Download Presentation SLIDES Here Building a Tool for Security Consultants: A Customized Source Code Scanner |
Play Video in a New Window Download Presentation SLIDES Here "Help Wanted" - 7 Things You Need to Know AppSec and InfoSec Employment |
Play Video in a New Window Download Presentation SLIDES Here Industry Analyst with Forrester Research |
||||||
| 11:00-11:45 |
Play Video in a New Window Download Presentation SLIDES Here CLASP (Comprehensive, Lightweight Application Security Process) |
Play Video in a New Window Download Presentation SLIDES Here Security in Agile Development |
|||||||
| 12:00-12:45 |
Play Video in a New Window Download Presentation SLIDES Here Next Generation Cross Site Scripting Worms |
Play Video in a New Window Download Presentation SLIDES Here Security of Software-as-a-Service (SaaS) |
Play Video in a New Window Download Presentation SLIDES Here Open Reverse Benchmarking Project |
||||||
| 12:00-13:00 | Capture the Flag Status
LUNCH - Provided @ TechExpo |
||||||||
| 13:00-13:45 |
Play Video in a New Window Download Presentation SLIDES Here NIST SAMATE Static Analysis Tool Exposition (SATE) |
Play Video in a New Window Download Presentation SLIDES Here Lotus Notes / Domino Web Application Security |
|||||||
| 14:00-14:45 |
Play Video in a New Window Download Presentation SLIDES Here Practical Advanced Threat Modeling |
Play Video in a New Window Download Presentation SLIDES Here The Owasp Orizon Project: Towards Version 1.0 |
|||||||
| 15:00-15:45 |
Play Video in a New Window Download Presentation SLIDES Here Off-Shoring Application Development? Security is Still Your Problem |
Play Video in a New Window Download Presentation SLIDES Here A Security Architecture Case Study |
|||||||
| 16:00-16:45 |
Play Video in a New Window Download Presentation SLIDES Here Vulnerabilities in Application Interpreters and Runtimes |
Play Video in a New Window Download Presentation SLIDES Here Cryptography for Penetration Testers |
Play Video in a New Window Download Presentation SLIDES Here Memory Corruption and Buffer Overflows |
||||||
| 17:00-17:45 |
Event Wrap-Up / Speaker & CTF Awards and Sponsor Raffles |
||||||||
Video content produced, processed and posted by www.MediaArchives.com |
|||||||||
The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to develop, purchase, and maintain applications that can be trusted on the internet. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. OWASP advocates approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. More information on the Open Web Application Security Project can be found at www.owasp.org
OWASP Conference San Jose Nov 14, 2007 |
||
|---|---|---|
| Track 1: Nov 14, 2007 | Track 2: Nov 14, 2007 | |
| 07:30-08:50 | Doors Open for Attendee/Speaker Registration | |
| 09:00-09:10 |
Welcome to OWASP & WASC AppSec 2007 Conference Keynote: eBay Application Security Program
An Introduction to WASC and Its Projects (pdf)
Using OWASP for Application Security (VERY LARGE - 66MB - ppt) |
|
| 9:10-10:00 | ||
| 10:00-10:30 | ||
| 11:20-12:20 |
Play Video in a New Window Download Presentation SLIDES Here For My Next Trick... Hacking Web 2.0 (ppt) |
"Video Unavailable"
Backdoors and other Developer Introduced 'Features' (ppt) |
| 13:45-14:30 |
Play Video in a New Window Download Presentation SLIDES Here CSRF: Danger, Detection, and Defenses Introducing two new OWASP CSRF Tools (ppt) |
Play Video in a New Window Download Presentation SLIDES Here WASC Distributed Open Proxy Honeypot Project (ppt) |
| 14:30-15:10 |
Play Video in a New Window Download Presentation SLIDES Here Defeating Web 2.0 Attacks without Recoding Applications (ppt) |
Play Video in a New Window Download Presentation SLIDES Here Dangers of Third Party Content (ppt) |
| 15:30-16:40 |
OWASP Projects Overview [No PPT] |
Web Browser (In)-Security - "Past, Present, and Future" (ppt) |
| 17:00-18:00 |
Panel: “Building an Effective Application Security Assurance Program” |
OWASP Leader Meeting (see meeting agenda here) |
|
|
|
|
CLICK HERE for the Full Agenda from the San Jose OWASP 2007 Conference
OWASP Conference San Jose Nov 14, 2007 |
||
|---|---|---|
| Track 1: Nov 14, 2007 | Track 2: Nov 14, 2007 | |
| Doors Open for Attendee/Speaker Registration | ||
| 10:50-11:30 |
|
Play Video in a New Window Download Presentation SLIDES Here Start Rolling with Rails Security (ppt) |
| 11:30-12:30 |
|
Play Video in a New Window Download Presentation SLIDES Here Securing Java Server Faces Against the OWASP Top 10 (ppt) |
| 13:45-14:30 |
|
Play Video in a New Window Download Presentation SLIDES Here .Net Web Services Hacking - Scan, Attacks and Defense (ppt) |
| 14:30-15:20 |
|
Play Video in a New Window Website Vulnerability Statistics |
| 15:40-16:30 |
|
Play Video in a New Window Session Management Security and Assessment Techniques |
Metadata includes: www.OWASP.org - The Open Web Application Security Project Foundation - www.OWASP.tv - Your Source for AppSec and InfoSec Video - Community, Organizations, Tools, Web, Internet, Forums, Chapters, Black Hat, White Hat, Blackbox, Whitebox, Hack, Hacking, Security, Invasion, NIST, SAMATE, PCI, FPI, WHID, SaaS, Spam, Bots, Malware, Analysis, Zero-Day, Exploits, Java, Fuzzing, Fuzzer, Flash, Parameter, SQL Injection, Spearphishing, Firewalls, Pen Testing, Source Code, Memory, Penetration Testing, Vulns, Vulnerabilities, Open Source, Cross-Site, Scripting, Threat Modeling, Cryptography, Crypto, Agile, DHS, Software, Google, Layer, Financial, Coding, Secure, Card Data, Enterprise, Firewall, Orizon, Off-Shoring, Outsourcing, Interepreters, Runtimes
