Thursday, August 10, 2017

OWASP World Tour



This year the strategic goal of OWASP is to raise awareness and spread application security knowledge world-wide by hosting a training world tour.  The 2017 world tour will have three, free mass application security training events.  Each one-day AppSec training course will teach 500 developers, software testers and entry level application security professionals core security topics. 

Our goal is that each training will combine general security principles such as the principle of least privilege, using secure defaults, reducing attack surface with AppSec specific topics such as parameterized queries to prevent SQLi and input validation and encoding.  We are also interested in teaching how OWASP Projects can assist in developing secure software. 

As part of the OWASP World Tour we are inviting all professional trainers to apply to the Call for Training for your opportunity to train in Tokyo, Boston, or Tel Aviv.  Training will close in this month, so apply today!  

If you are interested or know someone who is interested in attending the OWASP World Tour near you, please keep an eye on the OWASP Blog or OWASP World Tour Wiki Page for registration.  

Labels: , ,

Thursday, November 24, 2016

Opportunities to Present at OWASP AppSec Europe


AppSec Europe seeks to bring together developers and security professionals at all points in their careers to be the thriving global community that drives visibility and evolution in the safety and security of the world’s software.  We understand that robust security requires diversity of thought and practitioners.  We also know that a conference that meets the needs of our community must provide a buffet of learning and teaching experiences.  We are currently seeking submissions for the following in conference events:



  • Arsenal: Do you have an opensource tool to share with the world?  The AppSec Arsenal is the place to stand out from the crowd and demo your open source tool to potential users and collaborators. Successful applicants will have grown beyond proof of concept and represent a range of tools from the well known, to the newly established; the point-solution to the broad.  Watch for submission updates.

  • Lightning Training:  Important training comes in all sizes.  Our Lightning training sessions are the perfect 1-2 hour training on the go.  Your Lightning training session will be free to the public and can be in lecture or hands on mode. This a great place teach a concept swiftly, or allow new trainers to get experience. Apply for your Lightning training now!

  • Lightning Talks: Simplicity is beautiful and provocative ideas don't necessarily take an hour to express. Lighting Talks are the place to share everything from exciting vulnerabilities, to humorous lessons learned, to new ways of securing an application in 10-15 minuets.  Share your idea on the OWASP stage!

  • Activities: Conferences aren't all talk, sometimes you just need to DO! So whether it’s a Capture the Flag event, an Escape room, lock picking demonstrations or something else we want to facilitate your Activity. Preference given to those activities with a with a more security focused theme.  You can submit your Activity for May 11/12 here.

Pre-Conference Training:  AppSec Europe hosts paid single and multi-day training on the days leading up to the conference. Hands on training is strongly preferred to read more about our Training guidelines please read this previous blog post.


Deadline for proposals:  January 2, 2017
Notification to trainers: January 23, 2017
Training: May 8, 9, 10

Present at our Conference:  The deadline for presenting at our conference is coming up! We are looking for “the next”, cutting edge research in the context of web applications, secure development, security management and privacy. Academic researchers and industry practitioners have the opportunity to share their latest findings with the rest of the community, including coverage via our media channels. We will consider particularly good presentations that have been submitted elsewhere. 

Submission deadline: January 9th, 2017
Notification of acceptance: February 6th, 2017
Conference days: May 11th – 12th 2017

Labels: , , , , , , , , ,

Wednesday, October 26, 2016

AppSecEu 2017 Call for Presentations and Training Now Open

The call for presentations and training are now open for AppSecEu 2017, which will take place in Belfast from May 8th to 12th 2017. OWASP's Global AppSec events serve a diverse audience of security professionals at all stages of their careers. We seek interesting perspectives and training to drive visibility and evolution in the safety and security of the world’s software.

Our topics of interest for talks include, but are not limited to the following:
  • Novel web vulnerabilities and countermeasures
  • New technologies, paradigms, tools
  • OWASP tools or projects in practice
  • Secure development: frameworks, best practices, secure coding, methods, processes, SDLC
  • Browser security
  • Mobile security and security for the mobile web
  • Cloud security
  • REST/SOAP security
  • Security of frameworks
  • Large-scale security assessments of web applications and services
  • Privacy risks in the web and the cloud
  • Management topics in Application Security: Business Risks, Awareness Programs, Project Management, Managing SDLC
OWASP Trainings should be practical in nature--hands-on class will receive stronger consideration.  Topics of interest for include but are not limited to:
  • Secure development: frameworks, best practices, secure coding, methods, processes, SDLC
  • Vulnerability analysis: code review, pentest, static analysis
  • Threat modelling
  • Mobile security
  • Cloud security
  • Browser security
  • HTML5 security
  • OWASP tools or projects in practice
  • New technologies, paradigms, tools
  • Privacy in web apps, Web services (REST, XML) and data storage
  • Operations and software security
  • Management topics in Application Security: Business Risks, Outsourcing/Offshoring, Awareness Programs, Project Management, Managing SDLC
While we understand that your submission might be a work in progress, we strongly encourage that all submissions be as thorough as possible to allow us to make the best decision.  The program committee will review your submission based on a descriptive abstract of your intended presentation. Feel free to attach a preliminary version of your presentation if available, or any other supporting materials.  Please review your proposal thoroughly as accepted abstracts and bios submitted will be published 1:1 on our site. If your presentation is accepted for inclusion in the conference program, you are free to submit a white paper describing your work, to be added to the website.                                                                                   
To ensure the best talks available are presented at AppSec Europe we are incorporating blind reading as part of our process. This means that names and job titles will be removed when the paper's abstract is being reviewed. Submissions for training will not be read blind.  All speakers will be given access to speaker mentorship, we especially encourage first time speakers to take advantage of this service.
Marketing and sales pitches will not be accepted in the talks or trainings.

Submit a Presentation
  • Submission deadline: January 9th, 2017
  • Notification of acceptance: February 6th, 2017
  • Conference days: May 11th – 12th 2017

Submit a Training
  • Deadline for proposals:  January 2, 2017
  • Notification to training providers: January 23, 2017
  • Training: May 8, 9, 10


Labels: , , , , , , ,