November 8 - 11, 2010: OWASP AppSec DC 2010, Washington (USA)

Ivan Buetler, COE of Compass Security, is going to participate at the OWASP AppSec DC 2010 in Washington. This conference in Washington will be a premier gathering of Information Security leaders.
Event date: November 8, 2010 9:00 AM to November 11, 2010 5:30 PM

Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 600-700 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.


Talk of Ivan Buetler, November 11, 2010
What makes the difference between a web application firewall and a web entry server? In the talk of Ivan Buetler you learn more about web entry servers, architecture, pre-authentication, shared memory based session store, session hiding and service level accesscontrol.

The talk will start from a clean apache web server that will then be turned into a reverse proxy, from where mod_security enables the web app firewall capabilities. In the next step, the audience will learn and see how to turn this WAF into a Pre-Auth engine with url based access controls and session hiding features.

At the end of the talk, we have setup a fully operational, secure and open source web entry server in front of Facebook.


Event location:  Walter E. Washington Convention Center
Link: Venue

Further links:

 

News

Compass organises Swiss Cyber Storm 3
10/22/10 - „Meet the Lead“ and „Meet the Geek“ – this is the slogan of the third international IT security conference "Swiss Cyber Storm 3" from 12 to 15 May 2011 in Switzerland. An event in two parts expects the participants, organised by the IT security service provider Compass Security AG (www.csnc.ch) and the HSR University of Applied Sciences Rapperswil. It will appeal to IT security responsible persons and CIOs as well as computer cracks. In the "Cyber Storm Briefings" security experts from Europe and the USA will present the latest research results. During the subsequent "Cyber Storm Wargames" participants may delve into the hacker world in a playful way and compete for a car valued CHF 30'000.

Live-Hacking-Sessions at it-sa shed light on attacking scenarios on Smart phones
9/13/10 - How (un)safe are iPhone, Blackberry, etc.? - Compass is going to answer this question in the frame of its performance at it-sa in Nuremberg (hall 12, booth 329). From 19 to 21 October 2010 the visitors of the fair will learn a lot about safety risks in connection with modern Smart phones. In a live demonstration at the "Forum Rot" different attacking methods of hackers will be demonstrated and analysed. In addition, Marco Di Filippo, as a security expert, is going to participate at the "High-Noon-Talk" on the topic of mobile security.

Fake job advertisement "Software Tester"
8/24/10 - Using various German Internet portals, a Mr Jackob Jochanson of itanalyticer is searching Software Testers in our name.

Practical workshops on the topic of Web Application Security facilitate proactive hacking defence
8/19/10 - On the occasion of the it-sa 2010 Compass Security AG conducts two workshops on „Web Application Security“. From 19 to 20 October, respectively from 21 to 22 October, the participants take on the role of the hacker and thus get to know the weapons of their opponents so far unknown to them. These especially designed events include a visit of the meeting point of the trade at the Congress Centre in Nuremberg (19 to 21 October 2010). Thus, workshop attendants gain an extra bonus: They benefit from short travelling distances, opportunities for networking, utilizing the infrastructure of the trade fair as well as being able to take part in the evening events.

August 23 - 27, 2010 - IT Security Week, Copenhagen (DK)
8/18/10 - Liga Distributions ApS will organize from August 23 to August 27 the IT Security Week in Copenhagen.