-
There is going to be a new project leader (Brian Shura : bshura73_at_gmail_dot_com) for WASSEC (Web Application Security Scanner Evaluation Criteria) as of today. The leadership change will help me free up some time to work on other projects. We've identified an excellent candidate who will take over WASSEC from where I left. I have already given him an overview of the project, its status and
-
OWASP Delhi Chapter is hosting a grand application security event in New Delhi, India. With a lot of Executives and business folks also attending the event, it clearly shows the attention web application security is getting in India and I am sure a lot of it could also be because India is one of the major offshore development hub for US projects and most of these companies sending projects
-
WASC-OWASP Party at Blackhat Blackhat Vegas is around the corner. Our WASC-OWASP party last year rocked with around 300 people showing up. There was a huge line outside the shadow bar and it was by far the best party at Blackhat last year. If you weren't able to make it last year, do not miss it this time. Get your wristband from breach's booth at Blackhat. Join the leading minds in web
-
SANS and WASC have organized a Web Application Security Summit in Vegas.
Web Application Security Summit
Jeremiah Grossman, Summit Chair
with Robert “RSnake” Hansen, Gary McGraw, and Caleb Sima
June 2-3, 2008 • Paris Hotel & Casino • Las Vegas, NV
On June 2-3, Various Application Security folks working in the enterprises will share the lessons learned in their application security initiatives.
-
RSA Conference 2008 is almost over. As usual there were so many companies showcasing their products and services or in some cases just a little bit of fun like video games, rock climbing, etc.
I personally think there were more companies talking about web application security then last year. We still need some more companies with secure SDLC solutions to come out there. In addition, there were
-
WASC meetup at RSA was a huge success. More then 100 people showed up and it was a lot of fun sharing ideas and experiences with our peers. I am posting some of the pictures I took below.
Caleb Sima(HP), Robert Auger(WASC)
Neil Daswani (Google), Robi papp (Accuvant)
Pool was so much fun.
Dawn Van Hoegaerdan (Whitehat Security), Jermiah Grossman, Rachel Miller (Shift Communiations)
-
I got this email yesterday and it immediately caught my attention, maybe due to the recent news about malware being installed via legitimate website. Or maybe most of the previous phishing attempts were about stealing username/passwords. This one is about installing something on their machine (which i am sure is some sort of malware). This might be a shift in the approach and of course it makes a
-
RSA conference is around the corner and a lot of people from the webappsec field would be coming over to the conference. This is a perfect opportunity to meet with your peers. To facilitate that, WASC is organizing a meetup on April 9, 2008 12pm to 2pm. Whitehat Security has graciously accepted to sponsor the event. Please click on the image to see a larger version of the invite.
Last year
-
Web Application Security Consortium and SANS has partnered together to define, train, test and certify the individuals. WASC is a leading web application security organization and SANS is a leader in training and certification. Together they have the subject matter expertise and process expertise to make this a huge success.
Why do we need this certification?
As more and more software is
-
I got a text message today which said like
From:TAX@internalrefunding.com
------Message-----
Subject: NOTICE
You have .30 IRS
UNITS pending for
refunding, complete
the form using
www.internalrefunding.com ASAP
My first reaction was "What the f***" but then I started thinking "Could it be IRS?", if yes, then "Why send a SMS?"
Then my paranoid mind started working and even though I haven't