Monday, December 15, 2014

AppSec EU 2015 - Call for Papers and Call for Research


Call For Papers is now open


Do you want to give a presentation in Amsterdam? 
Visit the Call For Papers page and send your proposal on time.
  • Submission of proposals byDecember 31st, 2014 
  • Notification of acceptance: January 26th, 2015
  • Publication of program: February 11th, 2015
  • Conference Date: May 21st-22nd, 2015

Call For Research is now open

Do you want to present a paper in Amsterdam? 
Visit the Call For Research page and send your proposal on time.
  • Submission deadline: January 20th, 2015
  • Notification of acceptance: February 20th, 2015
  • Final version due: April 1st, 2015 (tbc)
  • Conference date: May 21st-22nd, 2015

Monday, November 24, 2014

OWASP Connector November 24


OWASP Global Connector
November 24, 2014 | | www.owasp.org | Contact Us | Brought to you by the OWASP Foundation
Communications

OWASP Community Manager

Noreen Whysel
Please help us in welcoming the new OWASP Community Manager
Noreen
Noreen started earlier this month and will be focusing on Community engagement with projects, chapter initiatives and volunteer recruitment.
You can review Noreen's wiki bio HERE

OWASP Bug Week

OWASP Bug Week is coming soon! This week long online competition will kick off December 8th 00:00:01 PST. Find vulnerabilities in the web applications of well known companies through the bug bounty programs hosted on Bugcrowd and win cash bounties! Best bug wins a trip to AppSecUSA or AppSecEU. www.bugcrowd.com/bugbash

membership

Thank you to our New Corporate Members:

  • eLearn Security
  • Trend Micro
initiatives

Are you Game?

During the 2014 Waspy Award election, the leaders began a discussion focusing on awarding merits and recognizing participation that can be used to award our active leaders for their contributions.
We will be introducing gamification in the new OWASP Portal.
The updated portal will allow peer recognition for industry accomplishments as well as badge recognition for participation in various initiatives, projects, or chapters.
Stay Tuned - More Information on this will be distributed soon!
chapter

NEW OWASP CHAPTERS


  • Kanpur - India
  • Patagonia, Argentina - LATAM
  • Northeastern University Student Chapter - North America
BHAsia
CLICK HERE for information on advertising in the next connector
conferences

Global AppSec Events in 2014

LATAM Tour 2015
ATTN LATAM Chapter Leaders - The deadline to ensure your as a stop on the tour is November 30, 2014! Please submit your venue confirmation to Laura Grau
EU 2015 thumbnail
AppSec EU/Research 2015 (May 18 - 21, 2015, Amsterdam, NL)

AppSec USA 2015 (September 22 - 25, 2015, San Francisco, CA)

Upcoming Regional Events

OWASP Asia Tour 2014(October 22 - December 19, 2014) 8 stops across Asia
German OWASP Day (December 9, Hamburg, Germany)
OWASP - ISACA Conference (December 11-12, 2014) Rome, Italy
AppSec California (January 26-29, 2015, Santa Monica, CA)
OWASP London Cyber Security Week (January 26-30) London, UK
OWASP New Zeland Day (February 26 - 27) New Zeland
NYC OWASP HACKNYC 2015 (March 18 - 19, 2015, NYC, NY)
LASCON 2015 (October 19 - 22, 2015, Austin, TX)
AppSec Rio de la Plata 2015 November 17-20, 2015) Montevideo, Uruguay

Partner and Promotional Events

OWASP has partnered with these great events in beginning of 2014 to grow our community and build awareness around software security. If you want to learn more about OWASP's involvement or will be attending and want to help out contact us
International Conference on Corporate Espionage & Industrial Security (December 1 - 2, 2014) Ottawa, Canada
Suits and Spooks (December 14, 2014) Singapore
ICCS (January 5 - 8, 2015) New York, NY
CodeMash Conference (January 6 - 9, 2015) Sandusky, OH
SC Congress London (March 3, 2015) London, UK
Financial Services Cyber Security Summit, MENA (March 9-10, 2015) Mena, Dubai
Blackhat Asia (March 24-27, 2015) Singapore
Cyber Security Summit Europe (April 14-15, 2015) Prague, Czech Republic
Cloud Security World 2015 (May 19-21, 2015) New Orleans, LA
SC Congress Toronto (June 10 - 12, 2015) Toronto, Canada
Projects

OWASP Dependency Check Project Release

OWASP Dependency Check Project

The Dependency Check is a utility that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. Currently Java and .NET dependencies are supported; however, support for Node.JS, client side JavaScript libraries, etc. is planned. This tool can be part of a solution to the OWASP Top 10 2013 A9 - Using Components with Known Vulnerabilities.
The project team is pleased to announce the release of 1.2.6
Here is a summary of the updates:

  1. Fixed Reported false positives.
  2. The Maven plugin now uses the dependencies GAV as declared in the project/POM being scanned (thanks Erik!).
  3. Resolved issue #156 to ensure consistent results rather then cycling removed and added issues in Jenkins.
  4. The CLI now accepts Ant style paths for the '--scan' argument.
  5. The CLI now accepts an '--exclude' argument that accepts Ant style exclusions.
  6. When using the CLI you can now specify a file name for the output file (as long as the --format is not set to ALL). The file extension must be xml when --format is set to xml or '.htm' or '.html' for either of the HTML formated reports.
  7. The Nexus Analyzer has been disabled and replaced with the Central Analyzer.
  8. Updated the URLs to download the NVD CVE data to use the gzip version. The current URLs can be obtained from the dependencycheck.properties file

OWASP Snakes and Ladders

Having a training session, party or celebration with software developers, or with those learning to code at college, at school or at home? Print out a copy and play the new OWASP board game where application security controls are the virtuous behaviours (ladders), and vulnerabilities are the vices (snakes). Available for web applications in Chinese, Dutch, English, French, German and Spanish. The similar board game for mobile apps is just available in English currently.
To find out more or to download a copy, visit Snakes & Ladders.
You may also contact the project Colin Watson directly.


Social Media

OWASP Foundation Social Media

OWASP YouTube Channel
LinkedIn
Twitter
Google +
Facebook
Ning
StackOverflow


Monday, November 17, 2014

Chapters, Projects, Taxes and 378,223.12


This week the OWASP Foundation had to file the United States business taxes -- for the last (10) years it has been insightful watching OWASP grow for me

##For your bookmark the transparent details of these legal filings will be posted here shortly:

As a leader however I did however want to draw your attention to  $378,223.12.  Yes, OWASP Chapters around the world have funds of $378,223.12 US ear-marked at HQ OWASP. 

As a chapter leader you can redeem that money anytime with a receipt that follows the OWASP Chapter Handbook

As a global and legal charity I wanted to draw your attention to this. It is very important that chapters (and OWASP Foundation) USE their funds to further the actual mission of OWASP.  As each chapter conducts it's end of year wrap up meetings and 2015 planning, consider your chapters plan to invest in social events/outreach, work with Academia to build the next generation and/or retrain existing workforce, incentive using scholarships on projects, build support invest in maker-spaces, host mini-summits, project code-camps, research, <insert your great idea> its ok to experiment that is how OWASP was built.

https://docs.google.com/a/proactiverisk.com/spreadsheet/pub?hl=en_US&hl=en_US&key=0Atu4kyR3ljftdEdQWTczbUxoMUFnWmlTODZ2ZFZvaXc&output=html


=====

Need a FUN idea and current topic for your next chapter meeting?  How about Internet of Things (IoT)

Ask this question: 
 "Since homeowners aren’t experts in technology and security is NOT a Top 10 list, what are the attack surfaces did you think about while watching this video

>> PLAY THIS VIDEO <<


http://www.youtube.com/watch?v=2T934EyrTJI

Then after you have a interactive dialog and captured useful data "edit" the wiki" and help out on this NEW project and important project.  Think of other consumer and medical devices that are being connected to the internet

https://www.owasp.org/index.php/OWASP_Internet_of_Things_Top_Ten_Project

*Bonus points for this "hack" http://www.cnbc.com/id/101343245# sellers made $


## WANT TO INCLUDE A CARD GAME TOO THAT YOU CAN DO WITH GOOD SCOTCH?

OWASP brings you Cornucopia. <insert owasp band music>   OWASP Cornucopia is NOW AVAILABLE in 100% OWASP Branded Decks: (give them to your chapter members, give them to your co-workers, play cards in the park)

https://www.owasp.org/index.php/OWASP_Cornucopia

As a chapter leader you can also spend some of that $378,223.12 and buy some decks (pack of 10)  to hand out at your meetings and regional events.  To get them it is EASY, they can now be requested and charged back to your local chapter.
https://www.owasp.org/index.php/OWASP_Merchandise   then consider what other projects can benefit from the local chapter energy. 

In closing, over the last 10 years it has been great to see OWASP grow grow and grow like bamboo, the future is BRIGHT at OWASP locally and globally welcome to the new board members 

Semper Fi,

Tom Brennan
OWASP Foundation | Global Vice Chairman

Wednesday, November 5, 2014

Tuesday, November 4, 2014

OWASP Connector - November 4


OWASP Global Connector
November 4, 2014 | | www.owasp.org | Contact Us | Brought to you by the OWASP Foundation
Communications

2014 Global Board of Directors Election

The 2014 OWASP Global Board of Directors election has completed.
Please help us in welcoming the newly appointed board members. Their term will take affect January 1, 2015.


  • Jim Manico
  • Andrew van der Stock
  • Matthew Konda
  • We would like to thank all of the candidates for their time and energy they invested into this campaign.
  • Jim Manico - 382 votes
  • Andrew van der Stock - 302 votes
  • Matthew Konda - 204 votes
  • Bil Corry - 165 votes
  • Mateo Martinez - 143 votes
  • Israel Bryski - 131 votes
  • Tahir Khan - 92 votes
  • Nigel Phair - 72 votes
  • Timur Khrotko - 69 votes
  • Abbas Naderi Afooshte - 57 votes
  • Voter Summary
    • Total - 738
    • Abstain - 73
    • 738 of 1991 electors voted in this ballot
    • New Jersey Institute of Technology College of Computing Sciences
      Tom Brennan, outgoing board member has been appointed to The Alumni and Industry Advisory Board CCS Capstone Program at New Jersey Institute of Technology. NJIT provides a unique environment of real-world leaning to university, high school, and middle school students. This environment does not only integrate real world practices and resources into academic curricula but also integrates academic education into real world to add substantial value to existing real world projects.

      membership

      Thank you to our renewed Corporate Member:

      • Gotham Digital Science
      industry

      2014 CISO Survey

      TAKE THE SURVEY HERE
      OWASP is preparing the Global CISO report for 2014.

      We are conducting a survey among CISOs and senior information security managers with the aim of providing new insights about the state of application security across various industry sectors.
      This will help us align our efforts to better help solving the problems of that you face.
      Deadline for submission of the completed survey is November 10th 2014.
      TAKE THE SURVEY HERE
      conferences

      Global AppSec Events in 2014

      LATAM Tour 2015
      AppSec EU/Research 2015 (May 18 - 21, 2015, Amsterdam, NL)
      Call For Papers, Trainings, and Research are all now open - CLICK HERE FOR DEADLINES AND LINKS
      AppSec USA 2015 (September 22 - 25, 2015, San Francisco, CA)

      Upcoming Regional Events

      OWASP Asia Tour 2014
      German OWASP Day (December 9, Hamburg, Germany)
      AppSec California (January 26-29, 2015, Santa Monica, CA)
      NYC OWASP HACKNYC 2015 (March 18 - 19, 2015, NYC, NY)
      LASCON 2015 (October 19 - 22, 2015, Austin, TX)

      Partner and Promotional Events

      OWASP has partnered with these great events in beginning of 2014 to grow our community and build awareness around software security. If you want to learn more about OWASP's involvement or will be attending and want to help out contact us
      Infor Risk 360 (November 4 - 7, 2014) Kuala Lumpur
      Application Security Forum Western Switzerland (November 4 - 6, 2014) Geneva, Switzerland
      3rd Annual CISO Asia Summit & Roundtable (November 5 - 7, 2014) Singapore
      SECUREAMSTERDAM 2014 (Nov 6) Amsterdam, NE
      Fraud Summit - Orlando (November 6) Orlando, FL
      Hackfest The Return 2014 (November 7 - 8, 2014) Quebec, Canada
      Secure Dubai (November 17, 2014) Dubai, UAE
      Fraud Summit - Dallas (November 18) Dallas, TX
      CS Congress Chicago (November 18) Chicago, IL.
      National Cyber Security Career Fair (November 20 - 21, 2014)
      International Conference on Corporate Espionage & Industrial Security (December 1 - 2, 2015) Ottawa, Canada
      ICCS (January 5 - 8, 2015) New York, NY
      CodeMash Conference (January 6 - 9, 2015) Sandusky, OH
      SC Congress London (March 3, 2015) London, UK
      SC Congress Toronto (June 10 - 12, 2015) Toronto, Canada
      Projects

      New OWASP Projects

      OWASP KALP Project

      OWASP KALP Mobile Project is for the users around the world who want to access the Top Ten vulnerabilities on the go (on their mobile), download the Top Ten and Email it. This is light weight information of OWASP Top Ten. Any new additions to cheat sheets and prevention cheat sheets will automatically accessible on the mobile app.

      OWASP ASVS Assessment Tool

      OWASP ASVS Assessment Tool (OWAAT) is a tool, used to verify Web applications security conformance to the OWASP Application Security Verification Standard (ASVS). OWAAT is a Web-based tool and provides team work capabilities. It allows to create multiple assessment projects and assign assessment tasks to different users.

      OWASP Visual Crime Scene and Security Incident Education Project

      OWASP ASVS Assessment Tool (OWAAT) is a tool, used to verify Web applications security conformance to the OWASP Application Security Verification Standard (ASVS). OWAAT is a Web-based tool and provides team work capabilities. It allows to create multiple assessment projects and assign assessment tasks to different users.


      chapter

      NEW OWASP CHAPTERS


      • Lithuania - Europe
      • Estonia - Europe
      • Georgetown University Student Chapter - North America

      REACTIVATED CHAPTERS


      • Russia - Europe
      • Seattle - India
      Social Media

      OWASP Foundation Social Media

      OWASP YouTube Channel
      LinkedIn
      Twitter
      Google +
      Facebook
      Ning
      StackOverflow
      CLICK HERE for information on advertising in the next connector




      Thursday, October 23, 2014

      OWASP Connector


      OWASP Global Connector
      October 23, 2014 | | www.owasp.org | Contact Us | Brought to you by the OWASP Foundation
      Communications

      2014 Global Board of Directors Election

      Election FAQ
      Q. Who is eligible to vote?
      A. All paid or honorary members who's membership was active on 9/30/2014 should have already received their ballot via email.
      Q. I'm a member. Why didn't I get a ballot?
      A. Possible Causes:

      • For Individual Members - at the date the 'eligible voter' list was created (30 September 2014) your membership had not been renewed.
      • For Honorary Members - Honorary membership status must be actively renewed each year. If your honorary membership expired, and you did not actively renew by the 'eligible voter' date you were not included on the list.
      • Unsubscribe Issue. The voting instructions and link to ballot were sent out by the Simply Voting application. If you previously chose "Unsubscribe" to other emails sent from OWASP via Simply Voting, then you were 'not sent' the voter instruction email by the unsubscribe rule.

      Q. I didn't get notification to renew or did not realize I needed to renew. I still want to vote! What do I do?
      A.

      • The current voting period will remain open and it will be extended until October 31, 2014. We know that 1,956 names were on the list who received voting instructions and 463 (23%) have already voted.
      • For the 'missed members': We will open a special 'grace period' for the people who did not renew their membership in the 90 days before the Sept. 30, 2014 eligibility cutoff. Some may have done this by choice, others claim they did not receive renewal information.
      • Anyone who renews during this grace period ending Oct. 24 will become eligible to vote in the 2014 OWASP Board election. They will be sent the same voting instructions as the original 1,956. It will include the notice that voting is extended through the week of Oct. 27 - 31.
      • If you were a member as of 9/30/2014 but have not yet received your ballot please Contact Us.
      • Membership renewal Information
      • Honorary Membership Application

      membership

      Thank you to our new Corporate Member:

      • (ISC)2
      conferences

      Global AppSec Events in 2014

      LATAM Tour 2015 (April 6 - 24, 2015) More details coming soon
      AppSec EU/Research 2015 (May 18 - 21, 2015, Amsterdam, NL)
      CALL FOR PAPERS AND CALL FOR TRAINERS ARE NOW OPEN - Submission Deadline is December 31, 2014
      AppSec USA 2015 (September 22 - 25, 2015, San Francisco, CA)

      Upcoming Regional Events

      OWASP Romania InfoSec Conference 2014 (October 24, Bucharest, Romania)
      OWASP Tampa Day 2014 (November 3, Tampa, FL)
      German OWASP Day (December 9, Hamburg, Germany)
      AppSec California (January 26-29, 2015, Santa Monica, CA)
      NYC OWASP HACKNYC 2015 (March 18 - 19, 2015, NYC, NY)
      LASCON 2015 (October 19 - 22, 2015, Austin, TX)

      Partner and Promotional Events

      OWASP has partnered with these great events in beginning of 2014 to grow our community and build awareness around software security. If you want to learn more about OWASP's involvement or will be attending and want to help out contact us
      Fraud Summit - New York (October 21, 2014) New York, NY
      Global APT Defense Summit (October 22, 2014) New York, NY
      ISSA International Conference (October 22 - 23, 2014) Orlando, FL
      Infor Risk 360 (November 4 - 7, 2014) Kuala Lumpur
      Application Security Forum Western Switzerland (November 4 - 6, 2014) Geneva, Switzerland
      3rd Annual CISO Asia Summit & Roundtable (November 5 - 7, 2014) Singapore
      SECUREAMSTERDAM 2014 (Nov 6) Amsterdam, NE
      Fraud Summit - Orlando (November 6) Orlando, FL
      Hackfest The Return 2014 (November 7 - 8, 2014) Quebec, Canada
      Secure Dubai (November 17, 2014) Dubai, UAE
      Fraud Summit - Dallas (November 18) Dallas, TX
      CS Congress Chicago (November 18) Chicago, IL.
      National Cyber Security Career Fair (November 20 - 21, 2014)
      International Conference on Corporate Espionage & Industrial Security (December 1 - 2, 2015) Ottawa, Canada
      ICCS (January 5 - 8, 2015) New York, NY
      CodeMash Conference (January 6 - 9, 2015) Sandusky, OH
      SC Congress London (March 3, 2015) London, UK
      SC Congress Toronto (June 10 - 12, 2015) Toronto, Canada
      education
      globe

      OWASP en Espanol

      Los invitamos a nuestro proximo evento webcast en espaƱol a ser realizado el dia miƩrcoles 29 de Octubre a las 19 horas de Madrid (GMT+2).
      Charla: El Proyecto GoLISMERO: Como auditar aplicativos web de manera facil
      CLICK AQUI para mas detalles.


      chapter

      REACTIVATED CHAPTERS


      • Clju - Europe
      • Ahmedabad - India
      Social Media

      OWASP Foundation Social Media

      OWASP YouTube Channel
      LinkedIn
      Twitter
      Google +
      Facebook
      Ning
      StackOverflow
      contrast
      CLICK HERE for information on advertising in the next connector