Friday, March 20, 2015

OWASP March 19 Connector


OWASP Global Connector

March 19, 2015 || www.owasp.org | Contact Us | Brought to you by the OWASP Foundation
Communications

2015 Strategic Goals

OWASP Adrenaline

OWASP and the 2015 LATAM tour promoted on Mundo Hacker TV

membership

Corporate Members

Conference

AppSec EU 2015 Updates

AppSec USA 2015 Call for Training Open

OWASP SAMM Project Summit

2015 LATAM Tour

Partner and Promotional Events

chapters

New OWASP Chapters

Chapter Transitions

projects

OWASP Dependency-Track 1.0.0 Released

OWASP Vicnum Project Updated

OWASP Dependency Check 1.2.9 released

CISO Guide Translated to Spanish

Social Media

OWASP Foundation Social Media




Communications
OWASP Communications

Where do we go from here - OWASP releasing strategic goals for 2015!

by Tobias Gondrom, Chairman of the Board


Over the last years OWASP has grown and further followed our successful path improving Web and Application Security around the world. Today, our organization is in great shape and we are building up to what is promising to become a fantastic year 2015 for OWASP!
In the previous years we frequently set strategic goals to focus our global activities and to further our mission in specific and measurable ways. It is important to note that these goals are by no means a view to limit our community activity on only these goals. But rather the goals are to inspire new actions in addition to our already many ongoing great activities and to focus some of our efforts where we see great potential for OWASP and our mission to make application security more visible around the world.
This year we wanted to include more community feedback into these goals. In January, we sent out a survey to the OWASP Community asking for your thoughts on our strategic goals for 2015. And we received an amazing high turnout and feedback from over 1,100 people responding to our survey. Thank you all for that! Your feedback was extremely valuable and greatly appreciated! It guided our priorities in 2015 and beyond. And we also received a lot of messages from volunteers in the survey who want to join some of the activities on these goals. Don't worry we will get back to you on this, now.
Today we proudly release the following three strategic goals for 2015:

  • Build a scalable OWASP training program that spreads security training around the world.
  • Strengthen OWASP chapters and increase Chapter's abilities to spread the message of OWASP through locally organized and run events.
  • Mature the OWASP Projects Platform: Provide the OWASP projects community a mature project platform to encourage senior developers to participate in the various and many OWASP projects.
For More details on these goals and some of the actions we plan to do to achieve them, please take a look at our WIKI PAGE
Over the recent months and years, we already see amazing new chapter activities, project work and a lot of people from the community joining as volunteers and leaders. We are an open community organisation, and every activity is driven by you, our thousands of volunteers, members and leaders around the world. So if you have an idea how to contribute to the goals above (or any other exciting OWASP activity), we like to hear from you. If you like to join one of our many activities, please let us know, join the community list (owasp-community@lists.owasp.org, free to join for everyone) and post your interest or idea there to find other interested people to join you, or write to our community manager Noreen Whysel.
We want you to get involved!
YOU are OWASP - OWASP needs YOU!
With that, I wish all of us an amazing and exciting time ahead.
Tobias Gondrom, Chairman of the Board


OWASP Adrenaline


2014 OWASP Annual Report Call for Content

The OWASP Foundation is looking for exciting and illustrative success stories from YOU, the community for inclusion in our 2014 Annual Report. This years theme is simply: Growing, Learning, Sharing, Leading.
Tell us how you and your team worked to spread the OWASP mission [link to mission statement] in 2014. Here are some ideas but feel free to be creative!
  • How did your local/regional/global collaborate spread security awareness?
  • What types of educational outreach did you and/or your team accomplish?
  • How did you and/or your team leverage the OWASP platform to inspire non security professionals to turn their attention to application security?
  • Where did you leave a BIG OWASP footprint?
  • How did YOU benefit from the different facets of the OWASP platform?
Submit your content - articles, pictures, ideas [here] by April 14, 2015. This is your opportunity to share with the world why you participate. We want everyone to contribute! Everyone's story is important to the Foundation. Become globally famous by submitting your picture and/or brief bio so we can be sure to give you credit for your contribution. Of course, you may also request to remain anonymous if you prefer.

OWASP and 2015 LATAM Tour represented on Mundo Hacker TV

OWASP was represented on Mundo Hacker TV by Fabio Cerullo
CLICK HERE to watch the entire interview.


Membership
OWASP Membership

New Corporate Members

Renewed Corporate Members


Conference
OWASP Events

OWASP AppSec EU Updates

The Keynotes have been published and the program is taking shape!
Tuesday 19th May, 2015

Wednesday 20th May, 2015

Thursday and Friday 21st and 22nd May, 2015
Conference Days including: Keynotes, CISO, DEV, Hack, Ops, and Research talks, HackPra Allstars, Hands on sessions, and more ...

AppSec USA 2015 Call For Training Is Open

OWASP is soliciting training providers for the AppSec USA Conference.
Please submit via this Google Form.
Submission Deadline is April 15, 2015
We are interested in all topics related to Web Application Security and OWASP, in particular, but not limited to (these are just examples):

  • Secure development: frameworks, best practices, secure coding, methods, processes, SDLC
  • Vulnerability analysis: code review, pentest, static analysis
  • Threat modelling
  • Cloud Security
  • Browser Security
  • HTML5 Security
  • OWASP tools or projects in practice
  • New technologies, paradigms, tools
  • Privacy in web apps, Web services (REST, XML) and data storage
  • Operations and software security
  • Management topics in Application Security: Business Risks, Outsourcing/Offshoring, Awareness Programs, Project Management, Managing SDLC
More information on the Call for Training can be found HERE

OWASP SAMM Project Summit

Join us for the first OWASP SAMM Project Summit in Dublin March 27-28.
Friday is User Day covering talks, training, and round tables followed by a social event.
Saturday is Project Day covering the release of version 1.1, workshops, and roadmap discussions
Participate and steer one of our great flagship projects to the next level!
Details and registration can be found HERE. Follow us on twitter @OwaspSAMM

LATAM Tour 2015


    Agenda
  • Santiago, Chile: April 8-9, 2015
  • Patagonia, Argentina: April 10, 2015
  • Bucaramanga, Colombia: April 14, 2015
  • Montevideo, Uruguay: April 15-16, 2015
  • Lima, Peru: April 17-18, 2015
  • Santa Cruz, Bolivia: April 17-18, 2015
  • San Jose, Costa Rica: April 21, 2015
  • Guatemala, Guatemala: April 21-22, 2015
  • Buenos Aires, Argentina: April 23-24, 2015
  • Caracas, Venezuela: April 23-24, 2015


Partner and Promotional Events

Info Security Indonesia Conference (March 24, 2015) Jakarta, Indonesia
BlackHat Asia 2015 (March 24-27, 2015) Singapore. OWASP members receive $200 off briefings using code BRow200.
(ISC)2 SecureIreland Conference 2015 (March 31, 2015) Dublin Ireland. OWASP Members receive 20% off general event fees. Discount code OWASPISSCIRE
Cyber Security Summit Europe - Financial Sector (April 14-15, 2015) Prague, Czech Republic. OWASP Members receive 20% off general event fees. Discount code CSSOW
AppsWorld Germany 2015 (April 22-23, 2015) Berlin, Germany
AppsWorld North America 2015 (May 12-13, 2015) San Francisco, CA
SANS CyberTalent Fair (May 14-15, 2015) Virtual, online
International Conference on Cyber Security (ICCS) (May 16-17, 2015) City of Redlands, CA. OWASP members receive 25% off the general event fee. Discount code ICCSOWASP
Cloud Security World 2015 (May 19-21, 2015) New Orleans, LA..OWASP members receive a 25% discount off standard event fee. Discount code CLD15-OWASP
Hack In the Box (May 26-29, 2015) OWASP members receive 20% off by using discount code OWASP-HITB2015AMS
SC Congress Toronto (June 10 - 12, 2015) Toronto, Canada. Register with your @owasp email address and receive a discount.
EuroPython 2015 (July 20-26, 2015) Bilbao, Spain
Info Security Malaysia Conference (August 6, 2015) Kuala, Lumpur

bh europe contrast january coalfire

chapters
OWASP Chapters

New Chapters

Southern New Hampshire - Chapter Leaders - James Burroughs and Edmond Holohan
Knoxville, TN - Chapter Leader - Daniel Harvey
Bihar, India - Chapter Leader - Nishant
Northern Sweden - Chapter Leaders - Markus Örebrand and Magnus Hultdin

Chapter Transitions

Guatemala - New Chapter Leaders - Pablo Barrera and Camilo Fernandez

Busan, Korea - Chapter Leaders - Jang-Goon Sohn (Treasurer), Park Chang-Hyun, and Jang Byeong-jo

Share your chapter's successes! Submit your stories here

projects
OWASP Projects

OWASP Dependency-Track 1.0.0 Released

Dependency-Track is a webapp that allows organizations to document the use of third-party components across multiple applications and versions. Further, it provides automatic visibility into the use of components with known vulnerabilities. Dependency-Track compliments the wildly successful and highly useful Dependency-Check project by embedding its core engine and fulfilling additional use cases. It's another tool to combat the A9 problem.
You can get more information about the project and the release HERE

OWASP Vicnum Project Updated

The OWASP Vicnum Project has been updated to include a vulnerable XXE VM at http://xxe.sourceforge.net/
This VM was used in recent CTF events including the Breaking Bad challenge event at AppSec USA 2013 in NYC.
As with other vulnerable or broken apps, the basic goal of the project is to:
  • Test web application scanners
  • Test manual attack techniques
  • Test source code analysis tools
  • Look at the code that allows the vulnerabilities
  • Test web application firewalls
  • Have a little fun

OWASP Dependency Check 1.2.9 released

The OWASP Dependency-check team is pleased to announce the release of 1.2.9! This release contains general maintenance, upgrading dependent libraries, minor bug fixes, etc.
Please visit the documentation site for information on obtaining the new version (CLI, Maven Plugin, Ant, Task, Jenkins Plugin)
The changes of note are:
  • The Maven plugin was reworked to correctly process child modules when creating an aggregate project. Included in the change were several other issues end users have contacted me about.
  • Reduced false negatives with regard to some versions of Spring.
  • Fixed issue #196 - Some JAR files do not contain POM files yet a full POM is available from Central (or alternatively Nexus). Both the Central and Nexus analyzers will now look for and retrieve the POM if one has not been found locally. A result of this change is that if both the Central and Nexus analyzer are disabled there is a chance of false negatives (i.e. the dependency could not be correctly identified as vulnerable).
  • Fixed issue #185 - Maven aggregate reports now display the project name that references vulnerable dependency.
We continue to get help from the github community! This release includes PRs from Ahmet Kiyak and Hans Joachim Desserud. Thanks for all your help!

OWASP CISO Guide Translated into Spanish

You can reference it HERE.

Social Media
OWASP Social Media

OWASP Social Media Sites



No comments: