Showing posts with label WASC. Show all posts
Showing posts with label WASC. Show all posts

Monday, August 11, 2008

WASSEC Project Leader Change Announcement

There is going to be a new project leader (Brian Shura : bshura73_at_gmail_dot_com) for WASSEC (Web Application Security Scanner Evaluation Criteria) as of today. The leadership change will help me free up some time to work on other projects.

We've identified an excellent candidate who will take over WASSEC from where I left. I have already given him an overview of the project, its status and the contributors. I will be helping him initially in the background until he comes upto speed and will continue to assist him should he need any help from me in the future. His Bio is mentioned below

"Brian Shura is in charge of web application security for a large financial institution. He regularly conducts application security assessments using both manual and automated techniques, and has led formal product evaluations of security scanners and web application firewalls.

Prior to his role in application security, Brian spent five years working as a developer on large Internet-facing websites. When not working on web application security initiatives, Brian enjoys badminton, fishing, and hiking the Appalachian Trail."

Thursday, June 19, 2008

WASC OWASP Party @ Blackhat

WASC-OWASP Party at Blackhat

Blackhat Vegas is around the corner. Our WASC-OWASP party last year rocked with around 300 people showing up. There was a huge line outside the shadow bar and it was by far the best party at Blackhat last year. If you weren't able to make it last year, do not miss it this time. Get your wristband from breach's booth at Blackhat.

Join the leading minds in web application security for cocktails and appetizers
at the Shadow Bar inside Caesar's Palace.

When: Wednesday, August 6, 7:30 PM – 9:30 PM
Where: Shadow Bar, Caesar's Palace, Las Vegas
RSVP: Visit the Breach Security booth at BlackHat to get your wristband
Contact: egoldberg@breach.com

Sponsored by:
Breach Security

Tuesday, April 15, 2008

Web Application Security Summit

SANS and WASC have organized a Web Application Security Summit in Vegas.

Web Application Security Summit
Jeremiah Grossman, Summit Chair
with Robert “RSnake” Hansen, Gary McGraw, and Caleb Sima
June 2-3, 2008 • Paris Hotel & Casino • Las Vegas, NV


On June 2-3, Various Application Security folks working in the enterprises will share the lessons learned in their application security initiatives. Case studies in application security initiatives will be presented and dozens of questions will be answered. In the last few years, there has been a huge surge in web application attacks since that around 70% of all web applications had security flaws...and now 80% of new malware is focused on the application layer.

Applications have become the easier attack target. With that change, the criminals added a new security challenge—not only must corporations and schools and governments ensure secure configuration and effective patch management, now they must also ensure the applications they deploy have no security flaws. The WhatWorks in Application Security Summit 2008 brings together the pioneers who have already faced the application security problem. If you are spending or about to spend a lot of money and want to make sure the investment actually improves security these are real users who can tell you what works and what doesn’t.


Agenda


  • Is this a developer problem or a security problem? What is the role of each and how do they work together?
  • What are the primary attack vectors criminals are using to compromise applications and which programming errors account for the vast majority of those attacks?
  • How can we ensure our programmers know the common security flaws and can consistently eliminate them from the code we are deploying? Training? Testing? Hiring? And how can we make sure our outsourced programmers and suppliers also have those skills?
  • How do you architect security into the development lifecycle? How do you implement a layered approach to application security? What is SDLC and is it enough?
  • In addition to the Credit Card Industry (PCI) Standard, what other standards demand improved application security and what do they specifically require?
  • Which application security software tools work best? Do we need a combination of these tools or will one suffice?
    • Black-box: web application scanners
    • White box: code reviewers
    • Application security firewalls
  • How often do the tools create false positives and what are the best practices for dealing with false positives? And much more…


This could be a great place to learn from other's experiences who have been in the hot seat and have real live experience and insight of what worked for them and what didn't and why.

You can get a 10% discount if you register early.
To register go to: https://www.sans.org/registration/register.php?conferenceid=11223 and use the discount, WASC10

Monday, November 05, 2007

Panel discussion on Website Vulnerability Disclosure during AppSec Conference on Nov 15

As most of you know that OWASP-WASC AppSec Conference is held in ebay between Nov12-Nov15 including the training sessions. There are very many exciting topics to look forward to in the conference and not to forget the vendor parties at the end of the day. One of the things i am excited about is the panel discussion on Website Vulnerability Disclosure (which i will be moderating). We have some really great people on the panel and i am expecting a great lively discussion as the topic is also a little bit touchy :)

The panelists are
1. Robert "RSnake" Hansen - CEO of SecTheory with his blog at "http://ha.ckers.org".
2. Bruce Lowenthal - Director of Oracle Security Alerts Group, Oracle
3. Zulfikar Ramzan - Advanced Threat Team, Symantec;
4. Katie Moussouris - Security Strategist, Microsoft
5. Christopher Ernst - US Secret Service, San Francisco Field Branch.

I am expecting this to be one of the best panel since it is not only a sensitive topic but also since we will have the corporate, hacker and govt/law point of view on the subject.

Since i have been working on the questions to ask during the panel discussion, i thought i will also take others opinion on what kind of questions they would like to be asked. So, if you have any suggestions, please feel free to send me an email or leave them as a comment on the blog.

Do plan to be there as it should be fun. The date/time of the panel discussion is
Nov 15, 16:30 - 17:30

Here is the entire conference agenda
http://www.owasp.org/index.php/7th_OWASP_AppSec_Conference_-_San_Jose_2007/Agenda

Conference Registration page (if you havent registered already) including the details on the vendor parties
http://www.owasp.org/index.php/7th_OWASP_AppSec_Conference_-_San_Jose_2007

Tuesday, September 04, 2007

OWASP & WASC AppSec 2007

The OWASP/WASC Black Hat cocktail party was so successful it only made sense to join forces again, this for an upcoming conference. OWASP & WASC AppSec 2007 is scheduled for Nov 12 – 15 @ eBay campus in San Jose, California. This will be an entire conference dedicated to web application security and something not to be missed. In fact, we’re a little nervous because the venue might be able to fit everyone (300 max) wanting to attend.

Currently we’re busy formalizing the agenda and coordinating the logistics with parties and events. If the wish list pans out, we’ll have an amazing speaker/topic line-up, a ton of industry experts in attendance, security professionals from all over silicon valley, and a hopefully a few surprises to go with it. The official announcement is below and I'll update the blog with new developments.

FYI: There are plenty of sponsorship opportunities for interested organizations.

OWASP and WASC have joined forces for this year's AppSec 2007 conference being held at eBay in San Jose, CA on Nov 12-15. A huge concentration of the industry leading experts will be in attendance presenting high quality web application security content. AppSec 2007 offers a unique opportunity for security professionals, software developers, and IT managers to get up to speed on the latest and greatest attack techniques, defense strategies, and industry trends in an atmosphere of peers. The conference format and venue is also perfect for networking and sharing experiences with others that are down in the trenches. AppSec 2007 expects to exceed all attendance records from the previously years, making space extremely limited. There's only room for approximately 300 attendees. So if you're planning to come, please register soon.

For more details and registration:
http://www.owasp.org/index.php/OWASP_&_WASC_AppSec_2007_Conference.

The conference also features:
1) Two full days of tutorials on a wide variety of web application security topics.
http://www.owasp.org/index.php/7th_OWASP_AppSec_Conference_-_San_Jose_2007/Training
2) A web services security track
3) Vendor services and technology expoConference

Location: The AppSec 2007 Conference will be held at eBay at their facility at: 2211 North First Street in San Jose, CA Nov 12th-15th.

Training Days: Novermber 12th-13th
Main Conference: November 14th-15th

Wednesday, August 22, 2007

WASC WASSEC Project - Update

Thank you all for your patience. We have received an overwhelming response from the WASSEC (Web Application Security Scanner Evaluation Criteria) project. To proceed with the project please

1. Please email wasc-wassec-subscribe@webappsec.org and reply to confirmation email.
2. It is moderated subscription so every contributor has to be approved to send messages to the list.
3. Once you are subscribed to the list, then email wasc-wassec@webappsec.org to post messages.

All further communication will be done through the mailing list. Please keep checking your junk mail folder in case some messages might go there. We are also in the process of setting up a wiki for the length of the project to post updates, etc. Until then I will be updating my blog with the project details.

Once again, thank you for your participation.

Monday, August 13, 2007

WASC Announcement: 'WASSEC Project' Call for Participants

WASC has announced a new project WASSEC (Web Application Security Scanner Evaluation Criteria). Currently WASC is seeking volunteers from various sections of the community including penetration testers, scanner vendors, security researchers and also end users to contribute to the project.

A brief description of the project

The Web Application Security Evaluation Criteria is a set of guidelines to evaluate web application security scanners on their identification of web application vulnerabilities and its completeness. It will cover things like crawling, parsing, session handling, types of vulnerabilities and information about those vulnerabilities. The goal of this project is to evaluate the technical aspects of the web application security scanners and NOT the features provided by it.

The project page can be found at
http://www.webappsec.org/projects/wassec/

If you would like to be involved with the project, please contact Anurag Agarwal (anurag.agarwal@yahoo.com)