Archive for the 'OWASP' Category

Upcoming Speaking Events and DeepSec Austria Slides

December 10, 2007

DeepSec Austria was a great event. You can get my slides here. I think fun was had by all but feel free to leave a comment if you were there!
I will be speaking at a few events in the new year (…plus a few more not yet confirmed).
OWASP Australia - Gold Coast (keynote)
Microsoft TechDays 2008 [...]

Notes from Helsinki

October 2, 2007

When you have a choice between Reindeer steak or Beef steak on your menu you know you are in Finland! I like Finland, it’s great. Really nice people and a lovely coastal environment. At this time of year for someone who still live in the South of France it is a little cold!
I [...]

How to Write Insecure Code

October 2, 2007

Who said security can’t be funny? This humorous article by Jeff Williams made me chuckle.

OWASP Helsinki - Tuesday October 2nd

September 27, 2007

If you promise not to mention the name Kimi Raikkonen you are welcome to the OWASP Helsinki chapter meeting next Tuesday where I will be speaking about lots of things software security.
Hope to see you there!

SecurityLinkUp is now an OWASP Project

September 25, 2007

SecurityLinkUp.com is now an OWASP project. The original code is being thrown away. Brian Bertacini and Sebastien Deleersnyder are project managers and developing a set of requirements now.

Thoughts on OWASP Day in Belgium

September 6, 2007

I am in Brussels airport waiting for a flight back to Toulouse. First off its so good to be back in Europe. Last week I scoured Chicago, SeaTac and Dulles airports for non-toxic food. I just had a nice entrecote, bernaise sauce and half bottle of Chenet. Bliss!
Today was a really good day. Around 100 people, [...]

OWASP Meetings (London Weds 5th, Brussels Thurs 6th)

September 3, 2007

I am planning to be speaking at both events Brussels  this week about the OWASP Web Evaluation and Certificaton project. I am really behind on this project but do plan to release a new draft by tomorow night.
If you are in London on Weds or Brussels on Thursday please drop by and share a beer.
http://www.owasp.org/index.php/London
http://www.owasp.org/index.php/Belgium 
OWASP Evaluation [...]

Software Security Assurance - State of the Art Report

August 30, 2007

3o0 + pages of comentary and opinions on everything software security.
http://iac.dtic.mil/iatac/download/security.pdf
Thanks to Rudy for sending this over.

55% of Application Security Vulnerabilities are Missed By Tools

June 28, 2007

Jeff Williams took over running OWASP from me way back when. No only is he a nice bloke, nearly 7 feet tall and has done a superb job with OWASP, but he’s super smart as well. I was sent some slides he was using to promote OWASP.
https://www.owasp.org/images/a/ad/OWASP_Overview_Spring_2007.ppt
Slide 4 is shown below and caught my eye. [...]

Principles of a Good Security Evaluation Criteria

June 25, 2007

I am working in the OWASP Web Certification Project and planning to make some serious progress this week. One of things I have done is to step back and think about what makes a good evaluation criteria. Here are some notes.
- Risk Based Security
- Assurance
- Unambiguous
- Repeatable
- Flexible
Risk Based Security
Risk based information security may not always be a [...]