[Owasp-Cluj] Fwd: OWASP March 19 Connector

Lucian Corlan lucian.corlan at owasp.org
Mon Mar 23 08:26:12 UTC 2015

---------- Forwarded message ----------
From: The OWASP Foundation <The_OWASP_Foundation at mail.vresp.com>
Date: Fri, Mar 20, 2015 at 12:25 AM
Subject: OWASP March 19 Connector
To: lucian.corlan at owasp.org

 [image: OWASP Global Connector]

March 17, 2015 || www.owasp.org
| Contact Us
| Brought to you by the OWASP Foundation
  [image: Communications] <#14c34249b4c0ed57_CommunicationsHeading> 2015
Strategic Goals <#14c34249b4c0ed57_GOALS> OWASP Adrenaline
<#14c34249b4c0ed57_ANNUAL> OWASP and the 2015 LATAM tour promoted on Mundo
Hacker TV <#14c34249b4c0ed57_TV>  [image: membership]
<#14c34249b4c0ed57_MembershipHeading> Corporate Members
<#14c34249b4c0ed57_CorpMem>  [image: Conference]
<#14c34249b4c0ed57_ConferenceHeading> AppSec EU 2015 Updates
<#14c34249b4c0ed57_EU> AppSec USA 2015 Call for Training Open
<#14c34249b4c0ed57_USA> OWASP SAMM Project Summit <#14c34249b4c0ed57_SAMM> 2015
LATAM Tour <#14c34249b4c0ed57_LATAM> Partner and Promotional Events
<#14c34249b4c0ed57_PartnerEvents>   [image: chapters]
<#14c34249b4c0ed57_ChapterHeading> New OWASP Chapters
<#14c34249b4c0ed57_NewChapters> Chapter Transitions
<#14c34249b4c0ed57_NewChapters>  [image: projects]
<#14c34249b4c0ed57_Projects> OWASP Dependency-Track 1.0.0 Released
<#14c34249b4c0ed57_Track> OWASP Vicnum Project Updated
<#14c34249b4c0ed57_Vicnum> OWASP Dependency Check 1.2.9 released
<#14c34249b4c0ed57_Check> CISO Survey Translated to Spanish
<#14c34249b4c0ed57_CISO>  [image: Social Media]
<#14c34249b4c0ed57_SocialMedia> OWASP Foundation Social Media
  [image: Communications]
 *OWASP Communications*
  Where do we go from here - OWASP releasing strategic goals for 2015! by
Tobias Gondrum, Chairman of the Board

Over the last years OWASP has grown and further followed our successful
path improving Web and Application Security around the world. Today, our
organization is in great shape and we are building up to what is promising
to become a fantastic year 2015 for OWASP!

In the previous years we frequently set strategic goals to focus our global
activities and to further our mission in specific and measurable ways. It
is important to note that these goals are by no means a view to limit our
community activity on only these goals. But rather the goals are to inspire
new actions in addition to our already many ongoing great activities and to
focus some of our efforts where we see great potential for OWASP and our
mission to make application security more visible around the world.

This year we wanted to include more community feedback into these goals. In
January, we sent out a survey to the OWASP Community asking for your
thoughts on our strategic goals for 2015. And we received an amazing high
turnout and feedback from over 1,100 people responding to our survey. Thank
you all for that! Your feedback was extremely valuable and greatly
appreciated! It guided our priorities in 2015 and beyond. And we also
received a lot of messages from volunteers in the survey who want to join
some of the activities on these goals. Don't worry we will get back to you
on this, now.

Today we proudly release the following three strategic goals for 2015:

   - Build a scalable OWASP training program that spreads security training
   around the world.
   - Strengthen OWASP chapters and increase Chapter's abilities to spread
   the message of OWASP through locally organized and run events.
   - Mature the OWASP Projects Platform: Provide the OWASP projects
   community a mature project platform to encourage senior developers to
   participate in the various and many OWASP projects.

For More details on these goals and some of the actions we plan to do to
achieve them, please take a look at our WIKI PAGE

Over the recent months and years, we already see amazing new chapter
activities, project work and a lot of people from the community joining as
volunteers and leaders. We are an open community organisation, and every
activity is driven by you, our thousands of volunteers, members and leaders
around the world. So if you have an idea how to contribute to the goals
above (or any other exciting OWASP activity), we like to hear from you. If
you like to join one of our many activities, please let us know, join the
community list (owasp-community at lists.owasp.org, free to join for everyone)
and post your interest or idea there to find other interested people to
join you, or write to our community manager Noreen Whysel

We want you to get involved!

YOU are OWASP - OWASP needs YOU!

With that, I wish all of us an amazing and exciting time ahead.

Tobias Gondrom, Chairman of the Board

  OWASP Adrenaline 2014 OWASP Annual Report Call for Content

The OWASP Foundation is looking for exciting and illustrative success
stories from YOU, the community for inclusion in our 2014 Annual Report.
This years theme is simply: Growing, Learning, Sharing, Leading.

Tell us how you and your team worked to spread the OWASP mission [link to
mission statement] in 2014. Here are some ideas but feel free to be

   - How did your local/regional/global collaborate spread security
   - What types of educational outreach did you and/or your team accomplish?
   - How did you and/or your team leverage the OWASP platform to inspire
   non security professionals to turn their attention to application security?
   - Where did you leave a BIG OWASP footprint?
   - How did YOU benefit from the different facets of the OWASP platform?

Submit your content - articles, pictures, ideas [here] by April 14, 2015.
This is your opportunity to share with the world why you participate. We
want everyone to contribute! Everyone’s story is important to the
Foundation. Become globally famous by submitting your picture and/or brief
bio so we can be sure to give you credit for your contribution. Of course,
you may also request to remain anonymous if you prefer.
  OWASP and 2015 LATAM Tour represented on Mundo Hacker TV

OWASP was represented on Mundo Hacker TV by Fabio Cerullo

to watch the entire interview.
  [image: Membership]
 *OWASP Membership*
  New Corporate Members

   - Software Improvement Group

Renewed Corporate Members

   - Aspect Security
   - BCC Risk Advisory
   - Denim Group
   - Oracle
   - Twitter

  [image: Conference]
 *OWASP Events*
  OWASP AppSec EU Updates

The Keynotes have been published and the program is taking shape!

Tuesday 19th May, 2015

   - Day One of the two day trainings
   - Day One of the Project Summit
   - Day One of the University Challenge

Wednesday 20th May, 2015

   - One Day Trainings
   - Day Two of the two day trainings
   - Day Two of the Project Summit
   - Day Two of the University Challenge

Thursday and Friday 21st and 22nd May, 2015

Conference Days including: Keynotes,
DEV, Hack, Ops, and Research talks
HackPra Allstars,
Hands on sessions, and more ...
AppSec USA 2015 Call For Training Is Open

OWASP is soliciting training providers for the AppSec USA Conference.

Please submit via this Google Form.

Submission Deadline is April 15, 2015

We are interested in all topics related to Web Application Security and
OWASP, in particular, but not limited to (these are just examples):

   - Secure development: frameworks, best practices, secure coding,
   methods, processes, SDLC
   - Vulnerability analysis: code review, pentest, static analysis
   - Threat modelling
   - Cloud Security
   - Browser Security
   - HTML5 Security
   - OWASP tools or projects in practice
   - New technologies, paradigms, tools
   - Privacy in web apps, Web services (REST, XML) and data storage
   - Operations and software security
   - Management topics in Application Security: Business Risks,
   Outsourcing/Offshoring, Awareness Programs, Project Management, Managing

More information on the Call for Training can be found HERE
OWASP SAMM Project Summit

Join us for the first OWASP SAMM Project Summit in Dublin March 27-28.

Friday is User Day covering talks, training, and round tables followed by a
social event.

Saturday is Project Day covering the release of version 1.1, workshops, and
roadmap discussions

Participate and steer one of our great flagship projects to the next level!

Details and registration can be found HERE.
Follow us on twitter @OwaspSAMM
LATAM Tour 2015

   - Santiago, Chile: April 8-9, 2015
   - Patagonia, Argentina: April 10, 2015
   - Bucaramanga, Colombia: April 14, 2015
   - Montevideo, Uruguay: April 15-16, 2015
   - Lima, Peru: April 17-18, 2015
   - Santa Cruz, Bolivia: April 17-18, 2015
   - San Jose, Costa Rica: April 21, 2015
   - Guatemala, Guatemala: April 21-22, 2015
   - Buenos Aires, Argentina: April 23-24, 2015
   - Caracas, Venezuela: April 23-24, 2015

   *Additional Information*
   - Call for Papers AND Training are now open. Submission deadline
   February 15, 2015
   - Sponsorship Opportunities are Available

Partner and Promotional Events

Info Security Indonesia Conference
(March 24, 2015) Jakarta, Indonesia

BlackHat Asia 2015
(March 24-27, 2015) Singapore. OWASP members receive $200 off briefings
using code BRow200.

(ISC)2 SecureIreland Conference 2015
(March 31, 2015) Dublin Ireland. OWASP Members receive 20% off general
event fees. Discount code OWASPISSCIRE

Cyber Security Summit Europe - Financial Sector
(April 14-15, 2015) Prague, Czech Republic. OWASP Members receive 20% off
general event fees. Discount code CSSOW

AppsWorld Germany 2015
(April 22-23, 2015) Berlin, Germany

AppsWorld North America 2015
(May 12-13, 2015) San Francisco, CA

SANS CyberTalent Fair
(May 14-15, 2015) Virtual, online

International Conference on Cyber Security (ICCS)
<http://www.iccs2015.iaasse.org/> (May 16-17, 2015) City of Redlands, CA.
OWASP members receive 25% off the general event fee. Discount code ICCSOWASP

Cloud Security World 2015
(May 19-21, 2015) New Orleans, LA..OWASP members receive a 25% discount off
standard event fee. Discount code CLD15-OWASP

Hack In the Box
(May 26-29, 2015) OWASP members receive 20% off by using discount code

SC Congress Toronto
(June 10 - 12, 2015) Toronto, Canada. Register with your @owasp email
address and receive a discount.

EuroPython 2015
(July 20-26, 2015) Bilbao, Spain

Info Security Malaysia Conference
(August 6, 2015) Kuala, Lumpur

  [image: bh europe]
contrast january]
  [image: chapters]
 *OWASP Chapters*
  New Chapters

*Southern New Hampshire*
- Chapter Leaders - James Burroughs and Edmond Holohan

*Knoxville, TN*
- Chapter Leader - Daniel Harvey

*Bihar, India*
- Chapter Leader - Nishant

*Northern Sweden*
- Chapter Leaders - Markus Örebrand and Magnus Hultdin
Chapter Transitions

- New Chapter Leaders - Pablo Barrera and Camilo Fernandez

*Busan, Korea*
- Chapter Leaders - Jang-Goon Sohn (Treasurer), Park Chang-Hyun, and Jang

*Share your chapter's successes! Submit your stories here
<support at owasp.org>*
  [image: projects]
 *OWASP Projects*
  OWASP Dependency-Track 1.0.0 Released

Dependency-Track is a webapp that allows organizations to document the use
of third-party components across multiple applications and versions.
Further, it provides automatic visibility into the use of components with
known vulnerabilities. Dependency-Track compliments the wildly successful
and highly useful Dependency-Check project by embedding its core engine and
fulfilling additional use cases. It's another tool to combat the A9 problem.

You can get more information about the project and the release HERE
OWASP Vicnum Project Updated

The OWASP Vicnum Project
has been updated to include a vulnerable XXE VM at

This VM was used in recent CTF events including the Breaking Bad challenge
event at AppSec USA 2013 in NYC.

As with other vulnerable or broken apps, the basic goal of the project is

   - Test web application scanners
   - Test manual attack techniques
   - Test source code analysis tools
   - Look at the code that allows the vulnerabilities
   - Test web application firewalls
   - Have a little fun

OWASP Dependency Check 1.2.9 released

The OWASP Dependency-check
team is pleased to announce the release of 1.2.9! This release contains
general maintenance, upgrading dependent libraries, minor bug fixes, etc.

Please visit the documentation site
for information on obtaining the new version (CLI,

The changes of note are:

   - The Maven plugin was reworked to correctly process child modules when
   creating an aggregate project. Included in the change were several other
   issues end users have contacted me about.
   - Reduced false negatives with regard to some versions of Spring.
   - Fixed issue #196 - Some JAR files do not contain POM files yet a full
   POM is available from Central (or alternatively Nexus). Both the Central
   and Nexus analyzers will now look for and retrieve the POM if one has not
   been found locally. A result of this change is that if both the Central and
   Nexus analyzer are disabled there is a chance of false negatives (i.e. the
   dependency could not be correctly identified as vulnerable).
   - Fixed issue #185 - Maven aggregate reports now display the project
   name that references vulnerable dependency.

We continue to get help from the github community! This release includes
PRs from Ahmet Kiyak
and Hans Joachim Desserud.
Thanks for all your help!
OWASP CISO Guide Translated into Spanish

You can reference it OWASP Vicnum Project
  [image: Social Media]
 *OWASP Social Media*
  OWASP Social Media Sites

   - OWASP YouTube Channel
   - LinkedIn
   - Twitter
   - Google +
   - Facebook
   - Ning
   - StackOverflow

  Click to view this email in a browser

If you no longer wish to receive these emails, please reply to this message
with "Unsubscribe" in the subject line or simply click on the following
link: Unsubscribe <http://cts.vresp.com/u?98bd849cad/d412b5f4f4/mlpftw>
  The OWASP Foundation
1200-C Agora Drive
Bel Air, Maryland 21014

Read <http://www.verticalresponse.com/content/pm_policy.html> the
VerticalResponse marketing policy.
  [image: Non-Profits Email Free with VerticalResponse!]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.owasp.org/pipermail/owasp-cluj/attachments/20150323/4f4d424e/attachment-0001.html>

More information about the Owasp-Cluj mailing list